Systems and methods for caching SPDM-based certificates
According to embodiments of the present disclosure, a certificate caching system and method is provided using Security Protocol and Data Model (SPDM)-enabled Baseboard Management Controller (BMC). The system time verification system and method include program instructions that may be executed on an Information Handling System (HIS) to obtain a certificate from a SPDM-enabled device configured in a target computing device, identify a cache associated with the target computing device, determine whether the certificate is a hardware bound certificate, and store the certificate in the cache based upon the determination.
1 . An Information Handling System (IHS) comprising:
at least one memory coupled to at least one processor, the at least one memory having program instructions stored thereon that, upon execution by the at least one processor, cause the IHS to:
obtain a certificate from a Security Protocol and Data Model (SPDM)-enabled device configured in a target computing device;
identify a Certificate Transparency (CT) list associated with the target computing device;
determine whether the certificate is a hardware bound certificate; and
store the certificate in the CT list based upon the determination;
obtain data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;
generate a score based upon the obtained data; and
add the certificate to the CT list or remove the certificate from the CT list based upon the score.
2 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:
for each SPDM-enabled device deployed in the target computing device, add a hardware bound certificate associated with the SPDM-enabled device to the CT list; and
when one of the SPDM-enabled devices is removed from the target computing device, remove its hardware bound certificate associated with the one SPDM-enabled device from the CT list.
3 . The IHS of claim 2 , wherein the program instructions, upon execution, further cause the IHS to:
at an ongoing basis, determine whether any of the certificates are valid or invalid; and
when one of the certificates is determined to be invalid, perform one or more remedial actions.
4 . The IHS of claim 3 , wherein the one or more remedial actions comprise at least one of;
stop communicating with the SPDM-enabled device associated with the one certificate, disable a slot associated with the SPDM-enabled device, and generate an alert message indicating the invalid certificate.
5 . The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to:
notify a SPDM daemon that the certificate is to be obtained from the CT list.
6 . The IHS of claim 5 , wherein the program instructions, upon execution, further cause the IHS to obtain the data during a SPDM authentication process.
7 . The IHS of claim 5 , wherein the program instructions, upon execution, further cause the IHS to remove the certificate from the CT list or replace another certificate with the certificate based upon the score.
8 . The IHS of claim 1 , wherein the program instructions are performed by a Baseboard Management Controller (BMC) configured in the IHS.
9 . A Security Protocol and Data Model (SPDM)-based certificate caching method comprising:
obtaining a certificate from a SPDM-enabled device configured in a target computing device;
identifying a Certificate Transparency (CT) list associated with the target computing device;
determining whether the certificate is a hardware bound certificate; and
storing the certificate in the CT list based upon the determination;
obtaining data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;
generating a score based upon the obtained data; and
adding the certificate to the CT list or removing the certificate from the CT list based upon the score.
10 . The SPDM-based certificate caching method of claim 9 , further comprising:
for each SPDM-enabled device deployed in the target computing device, adding a hardware bound certificate associated with the SPDM-enabled device to the CT list; and
when one of the SPDM-enabled devices is removed from the target computing device, removing its hardware bound certificate associated with the one SPDM-enabled device from the CT list.
11 . The SPDM-based certificate caching method of claim 10 , further comprising:
at an ongoing basis, determining whether any of the certificates are valid or invalid; and
when one of the certificates is determined to be invalid, performing one or more remedial actions comprising at least one of stopping communication with the SPDM-enabled device associated with the one certificate, disabling a slot associated with the SPDM-enabled device, and generating an alert message indicating the invalid certificate.
12 . The SPDM-based certificate caching method of claim 9 , further comprising:
notifying a SPDM daemon that the certificate is to be obtained from the CT list.
13 . The SPDM-based certificate caching method of claim 12 , further comprising obtaining the data during a SPDM authentication process.
14 . The SPDM-based certificate caching method of claim 12 , further comprising removing the certificate from the CT list or replacing another certificate with the certificate based upon the score.
15 . A computer program product comprising a non-transitory computer readable storage medium having program instructions stored thereon that, upon execution by a Baseboard Management Controller (BMC), cause the BMC to:
obtain a certificate from a Security Protocol and Data Model (SPDM)-enabled device configured in a target computing device;
identify a Certificate Transparency (CT) list associated with the target computing device;
determine whether the certificate is a hardware bound certificate; and
store the certificate in the CT list based upon the determination;
obtain data associated with how the certificate is obtained from an associated SPDM-enabled device, wherein the obtained data comprises at least one of a capacity of the CT list and a response time to obtain the certificate from the SPDM-enabled device;
generate a score based upon the obtained data; and
add the certificate to the CT list or remove the certificate from the CT list based upon the score.
16 . The computer program product of claim 15 , wherein the program instructions, upon execution, further cause the BMC to:
for each SPDM-enabled device deployed in the target computing device, add a hardware bound certificate associated with the SPDM-enabled device to the CT list; and
when one of the SPDM-enabled devices is removed from the target computing device, remove its associated hardware bound certificate associated with the one SPDM-enabled device from the CT list.
17 . The computer program product of claim 16 , wherein the program instructions, upon execution, further cause the BMC to:
at an ongoing basis, determine whether any of the certificates are valid or invalid; and
when one of the certificates is determined to be invalid, perform one or more remedial actions comprising at least one of stopping communication with the SPDM-enabled device associated with the one certificate, disabling a slot associated with the SPDM-enabled device, and generating an alert message indicating the invalid certificate.
18 . The computer program product of claim 15 , wherein the program instructions, upon execution, further cause an Information Handling System (IHS) to:
obtain data associated with how the certificate is obtained from an associated SPDM-enabled device;
generate a score based upon the obtained data;
add the certificate to the CT list or remove the certificate from the CT list based upon the score; and
notify a SPDM daemon that the certificate is to be obtained from the CT list.
19 . The computer program product of claim 18 , wherein the program instructions, upon execution, further cause the IHS to obtain the data during a SPDM authentication process.