IP Library Granted Patent US 12,608,322
Granted Patent B2
US 12,608,322 · App. 18/370,159 · Granted Apr 21, 2026

Techniques of encrypting BMC and bios firmware and data in flash memory

Inventors: Samvinesh Christopher (Suwanee, GA); Anurag Bhatia (Sugar Hill, GA); Winston Thangapandian (Suwanee, GA)
Assignee: AMERICAN MEGATRENDS INTERNATIONAL, LLC
G06F12/1408G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,608,322
App. No.
18/370,159
Granted
Apr 21, 2026
Kind
B2
Abstract

In an aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus is a BMC. The BMC receives data to be written to a storage. The BMC encrypts the data using a stream encrypt engine to generate encrypted data. The BMC writes the encrypted data to the storage. The BMC receives encrypted data read from the storage. The BMC decrypts the encrypted data using a stream decrypt engine to generate decrypted data. The BMC provides the decrypted data to a component of the BMC.

Claims (30)

1 . A method of operation of a baseboard management controller (BMC), the method comprising:

routing data to be written from a first hardware component of the BMC or a host of the BMC to a storage through a hardware data encrypt/decrypt component positioned in-line between the first hardware component and the storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component;

encrypting the data using a stream encrypt engine of the hardware data encrypt/decrypt component to generate encrypted data;

writing the encrypted data to the storage;

routing encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component; and

decrypting the encrypted data using a stream decrypt engine of the hardware data encrypt/decrypt component to generate decrypted data.

2 . The method of claim 1 , further comprising:

receiving a control command; and

providing the control command to the storage without encryption and decryption.

3 . The method of claim 1 , wherein encrypting the data comprises encrypting the data using a unique key associated with the stream encrypt engine.

4 . The method of claim 3 , wherein the unique key is derived from a unique identifier of the BMC.

5 . The method of claim 1 , wherein a size of the encrypted data equals a size of the data received to be written to the storage.

6 . The method of claim 1 , wherein the storage comprises a serial peripheral interface (SPI) flash memory.

7 . The method of claim 1 , wherein the data are a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC.

8 . A baseboard management controller (BMC) comprising:

a hardware data encrypt/decrypt component positioned in-line between a first hardware component and a storage, wherein the hardware data encrypt/decrypt component is separate from and external to the first hardware component, the hardware data encrypt/decrypt component comprising:

a stream encrypt engine configured to encrypt data to be written to the storage; and

a stream decrypt engine configured to decrypt encrypted data read from the storage;

a memory; and

a processing unit coupled to the memory and configured to:

route data to be written from the first hardware component to the storage through the hardware data encrypt/decrypt component including providing the data to the stream encrypt engine for encryption, wherein the stream encrypt engine provides the encrypted data to the storage; and

route encrypted data read from the storage to the first hardware component through the hardware data encrypt/decrypt component including providing the encrypted data to the stream decrypt engine for decryption.

9 . The BMC of claim 8 , wherein the processing unit is further configured to:

receive a control command; and

provide the control command to the storage without encryption and decryption.

10 . The BMC of claim 8 , wherein the stream encrypt engine is configured to encrypt the data using a unique key associated with the stream encrypt engine.

11 . The BMC of claim 10 , wherein the unique key is derived from a unique identifier of the BMC.

12 . The BMC of claim 8 , wherein a size of the encrypted data equals a size of the received data to be written to the storage.

13 . The BMC of claim 8 , wherein the storage comprises a serial peripheral interface (SPI) flash memory.

14 . The BMC of claim 8 , wherein the data is a part of firmware of the BMC or a part of firmware of a Basic Input/Output System (BIOS) of a host of the BMC.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0948 →
SECURITY INTEREST Recorded Apr 30, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 067274/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2023
From: CHRISTOPHER, SAMVINESH; BHATIA, ANURAG; THANGAPANDIAN, WINSTON
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 064955/0446 →
Continuity (1)
Related Publication 20250094360A1 · Mar 20, 2025
References Cited (26)
US 10515218B2 · Ghetie · 2019 [cited by examiner]
US 10747295B1 · Paaske · 2020 [cited by examiner]
US 10839080B2 · Khessib · 2020 [cited by examiner]
US 10867046B2 · Lin · 2020 [cited by examiner]
US 10868743B2 · Slaight · 2020 [cited by examiner]
US 11070566B2 · Nabeesa · 2021 [cited by examiner]
US 20110243332A1 · Akimoto · 2011 [cited by examiner]
US 20150026459A1 · Divakar · 2015 [cited by examiner]
US 20180096151A1 · Ghetie · 2018 [cited by examiner]
US 20180357425A1 · Swaminathan · 2018 [cited by examiner]
US 20190073478A1 · Khessib · 2019 [cited by examiner]
US 20190197261A1 · Yu · 2019 [cited by examiner]
US 20190340379A1 · Beecham · 2019 [cited by examiner]
US 20200320226A1 · Chitrak Gupta · 2020 [cited by examiner]
US 20210034791A1 · Singh · 2021 [cited by examiner]
US 20210051217A1 · Rahardjo · 2021 [cited by examiner]
US 20210218562A1 · Grobelny · 2021 [cited by examiner]
US 20210377019A1 · Preimesberger · 2021 [cited by examiner]
US 20220179674A1 · Goel · 2022 [cited by examiner]
US 20220188468A1 · Luciani · 2022 [cited by examiner]
US 20220374164A1 · Park · 2022 [cited by examiner]
US 20230161658A1 · Tung · 2023 [cited by examiner]
US 20230359369A1 · Muthiah · 2023 [cited by examiner]
US 20230409211A1 · Lin · 2023 [cited by examiner]
US 20250077082A1 · Lee · 2025 [cited by examiner]
Songjie Liang; Secure USB based File System for BMC Applications; IEEE:2017; pp. 228-233. [cited by examiner]