Initialization information storage virtualization system
An initialization information storage virtualization system includes a resource system that is coupled to a resource management system and that includes a processing system coupled to a System Control Processor (SCP) device. The SCP device creates a virtual initialization information storage and a virtual Trusted Platform Module (vTPM) in its secure memory subsystem. The SCP device then receives resource system initialization information and resource system initialization authentication information for the resource system from the resource management system, populates the virtual initialization information storage with the resource system initialization information, and populates the vTPM with the resource system initialization authentication information. When the SCP device receives an initialization information request from the processing system, the SCP device provides the resource system initialization information and the resource system initialization authentication information to the processing system.
1 . An initialization information storage virtualization system, comprising:
a resource management system; and
a resource system that is coupled to the resource management system and that includes:
a processing system; and
a System Control Processor (SCP) device that is coupled to the processing system and that is configured to:
program a secure memory subsystem in the SCP device to emulate a storage space and configure that storage space to store initialization information to create a virtual initialization information storage in the secure memory subsystem in the SCP device;
program the secure memory subsystem in the SCP device to emulate a virtual Trusted Platform Module (vTPM) interface, enable TPM request response engines, and populate register values to create a virtual TPM in the secure memory subsystem in the SCP device;
receive, from the resource management system, resource system initialization information for the resource system, and populate the virtual initialization information storage with the resource system initialization information;
receive, from the resource management system, resource system initialization authentication information for the resource system, and populate the vTPM with the resource system initialization authentication information;
receive an initialization information request from the processing system; and
provide, in response to the initialization information request, the resource system initialization information and the resource system initialization authentication information to the processing system.
2 . The system of claim 1 , wherein the SCP device is configured to:
receive, from the resource management system, a Software Bill Of Materials (SBOM) that identifies software resources in the resource system; and
store the SBOM in the secure memory subsystem in the SCP device.
3 . The system of claim 1 , wherein the SCP device is configured to:
receive, from the resource management system, a runtime image for the resource system, wherein the resource system initialization information includes a subset of the runtime image; and
store the runtime image in the secure memory subsystem in the SCP device.
4 . The system of claim 1 , wherein the SCP device is configured to:
receive, from the resource management system, a configuration profile for the resource system that defines a configuration of the resource system, wherein the resource system initialization information includes a subset of the configuration profile; and
store the configuration profile in the secure memory subsystem in the SCP device.
5 . The system of claim 1 , wherein the SCP device is configured to:
provide a Serial Peripheral Interface (SPI) endpoint; and
use the SPI endpoint to:
receive the initialization information request from the processing system, and provide the resource system initialization information and the resource system initialization authentication information to the processing system.
6 . The system of claim 1 , wherein the SCP device is configured to:
provide a Non-Volatile Memory express (NVMe) subsystem; and
use the NVMe subsystem to:
receive the initialization information request from the processing system, and provide the resource system initialization information to the processing system.
7 . A System Control Processor (SCP) device, comprising:
a System Control Processor (SCP) processing system; and
an SCP memory system that is coupled to the SCP processing system and that includes instructions that, when executed by the SCP processing system, cause the SCP processing system to provide an SCP engine that is configured to:
program a secure portion of the SCP memory system to emulate a storage space and configure that storage space to store initialization information to create a virtual initialization information storage in the secure portion of the SCP memory system of the SCP device;
program the secure portion of the SCP memory system to emulate a virtual Trusted Platform Module (vTPM) interface, enable TPM request response engines, and populate register values to create a virtual TPM in the secure portion of the SCP memory system of the SCP device;
receive, from a resource management system, resource system initialization information for a resource system that includes the SCP processing system, and populate the virtual initialization information storage with the resource system initialization information;
receive, from the resource management system, resource system initialization authentication information for the resource system, and populate the vTPM with the resource system initialization authentication information;
receive an initialization information request from a host processing system that is included in the resource system; and
provide, in response to the initialization information request, the resource system initialization information and the resource system initialization authentication information to the host processing system.
8 . The SCP device of claim 7 , wherein the SCP engine is configured to:
receive, from the resource management system, a Software Bill Of Materials (SBOM) that identifies software resources in the resource system; and
store the SBOM in the secure portion of the SCP memory system in the SCP device.
9 . The SCP device of claim 7 , wherein the SCP engine is configured to:
receive, from the resource management system, a runtime image for the resource system, wherein the resource system initialization information includes a subset of the runtime image; and
store the runtime image in the secure portion of the SCP memory system in the SCP device.
10 . The SCP device of claim 7 , wherein the SCP engine is configured to:
receive, from the resource management system, a configuration profile for the resource system that defines a configuration of the resource system, wherein the resource system initialization information includes a subset of the configuration profile; and
store the configuration profile in the secure portion of the SCP memory system in the SCP device.
11 . The SCP device of claim 7 , wherein the SCP engine is configured to:
provide a Serial Peripheral Interface (SPI) endpoint; and
use the SPI endpoint to:
receive the initialization information request from the host processing system, and provide the resource system initialization information and the resource system initialization authentication information to the host processing system.
12 . The SCP device of claim 7 , wherein the SCP engine is configured to:
provide a Non-Volatile Memory express (NVMe) subsystem; and
use the NVMe subsystem to:
receive the initialization information request from the host processing system, and provide the resource system initialization information to the host processing system.
13 . The SCP device of claim 12 , wherein the SCP engine is configured to:
provide a vTPM endpoint; and
use the vTPM endpoint to:
receive the initialization information request from the host processing system, and provide resource system initialization authorization information to the host processing system.
14 . A method for virtualizing storage for computing device initialization information, comprising:
programming, by a System Control Processor (SCP) device that is included in a resource system, a secure memory subsystem in the SCP device to emulate a storage space and configure that storage space to store initialization information to create a virtual initialization information storage in the secure memory subsystem in the SCP device;
programming, by the SCP device, the secure memory subsystem in the SCP device to emulate a virtual Trusted Platform Module (vTPM) interface, enable TPM request response engines, and populate register values to create a virtual TPM in the secure memory subsystem in the SCP device;
receive, by the SCP device from a resource management system, resource system initialization information for the resource system, and populating the virtual initialization information storage with the resource system initialization information;
receive, by the SCP device from the resource management system, resource system initialization authentication information for the resource system, and populating the vTPM with the resource system initialization authentication information;
receiving, by the SCP device, an initialization information request from a processing system that is included in the resource system; and
providing, by the SCP device in response to the initialization information request, the resource system initialization information and the resource system initialization authentication information to the processing system.
15 . The method of claim 14 , further comprising:
receiving, by the SCP device from the resource management system, a Software Bill Of Materials (SBOM) that identifies software resources in the resource system; and
storing, by the SCP device, the SBOM in the secure memory subsystem in the SCP device.
16 . The method of claim 14 , further comprising:
receiving, by the SCP device from the resource management system, a runtime image for the resource system, wherein the resource system initialization information includes a subset of the runtime image; and
storing, by the SCP device, the runtime image in the secure memory subsystem in the SCP device.
17 . The method of claim 14 , further comprising:
receiving, by the SCP device from the resource management system, a configuration profile for the resource system that defines a configuration of the resource system, wherein the resource system initialization information includes a subset of the configuration profile; and
storing, by the SCP device, the configuration profile in the secure memory subsystem in the SCP device.
18 . The method of claim 14 , further comprising:
providing, by the SCP device, a Serial Peripheral Interface (SPI) endpoint; and
using, by the SCP device, the SPI endpoint to:
receive the initialization information request from the processing system, and provide the resource system initialization information and the resource system initialization authentication information to the processing system.
19 . The method of claim 14 , further comprising:
providing, by the SCP device, a Non-Volatile Memory express (NVMe) subsystem; and
using, by the SCP device, the NVMe subsystem to:
receive the initialization information request from the processing system, and provide the resource system initialization information to the processing system.
20 . The method of claim 14 , further comprising:
providing, by the SCP device, a vTPM endpoint; and
using, by the SCP device, the vTPM endpoint to:
receive the initialization information request from the processing system, and provide resource system initialization authorization information to the processing system.