IP Library Granted Patent US 12,407,721
Granted Patent B2
US 12,407,721 · App. 17/381,641 · Granted Sep 2, 2025

Workspace-based fixed pass-through monitoring system and method for hardware devices using a baseboard management controller (BMC)

Inventors: Viswanath Ponnuru (Bangalore, IN); Rama Rao Bisa (Bangalore, IN); Chandrasekhar Mugunda (Austin, TX); Vineeth Radhakrishnan (Bangalore, IN); Shinose Abdul Rahiman (Bangalore, IN); Dharma Bhushan Ramaiah (Bengaluru, IN); Krishnaprasad K (Bengaluru, IN)
Assignee: Dell Products, L.P.
H04L63/1466G06F11/141H04L63/0218G06F2201/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,721
App. No.
17/381,641
Granted
Sep 2, 2025
Kind
B2
Abstract

An Information Handling System (IHS) includes multiple hardware devices, and a baseboard Management Controller (BMC) in communication with the plurality of hardware devices. The BMC includes executable instructions for monitoring the operating characteristics a hardware device that is operating in a fixed pass-through configuration with a workspace in which the workspace has been instantiated by a workspace orchestration service executed on the IHS. The executable instructions may determine that the operating characteristics are indicative of a security breach of the fixed pass-through configuration, and as such, may perform an operation to quarantine the one hardware device when the fixed pass-through configuration is determined to possess the security breach.

Claims (27)

1. An Information Handling System (IHS), comprising:

a plurality of hardware devices; and

a Baseboard Management Controller (BMC) in communication with the plurality of hard ware devices, the BMC comprising instructions that are executable by at least one processor to:

monitor one or more operating characteristics of at least one hardware device of the plurality of hardware devices to determine whether or not a fault comprising the one or more operating characteristics has been occurring at a rate that exceeds a specified threshold, wherein the at least one hardware device is operating in a fixed pass-through configuration with a workspace, wherein the workspace has been instantiated by a workspace orchestration service executed on the IHS, and wherein the one or more operating characteristics comprise at least one of: an input/output (I/O) device fault, a correctable error, an uncorrectable error, an improper memory access request, or a page fault, and wherein the at least one hardware device comprises a Security Protocol and Data Model (SPDM)-enabled hardware device;

perform a mutual authentication procedure with the SPDM-enabled hardware device to form a SPDM-based trusted network between the SPDM-enabled hardware device and the BMC;

determine that the operating characteristics are indicative of a security breach of the fixed pass-through configuration; and

perform an operation to quarantine the at least one SPDM-enabled hardware device when the fixed pass-through configuration is determined to possess the security breach by maintaining the quarantined at least one SPDM-enabled hardware device in a quarantine state until a firmware update procedure has been performed on the at least one SPDM-enabled hardware device.

2. The IHS of claim 1 , wherein the instructions are further executed to perform the operation to quarantine the at least one hardware device by removing the SPDM-enabled hardware device from the SPDM-based trusted network.

3. The IHS of claim 1 , wherein the instructions are further executed to perform the operation to quarantine the at least one hardware device by performing a device detach operation on the SPDM-enabled hardware device.

4. The IHS of claim 1 , wherein the instructions are further executed to perform the operation to quarantine the at least one hardware device by setting an Advanced Configuration and Power Interface (ACPI) state of the SPDM-enabled hardware device to an off state.

5. The IHS of claim 1 , wherein the fixed pass-through configuration comprises a Peripheral Component Interconnect Express (PCIe) pass-through configuration.

6. The IHS of claim 1 , wherein the fault comprises at least one of an input/output memory management unit (IOMMU) page fault, a VT-d page fault, or a Peripheral Component Interconnect Express (PCIe) uncorrectable error.

7. A fixed pass-through monitoring method comprising:

monitoring, using instructions stored in at least one memory and executed by at least one processor, one or more operating characteristics of at least one hardware device of a plurality of hardware devices to determine whether or not a fault comprising the one or more operating characteristics has been occurring at a rate that exceeds a specified threshold, wherein the at least one hardware device is operating in a fixed pass-through configuration with a workspace using a Baseboard Management Controller (BMC) in communication with the plurality of hardware devices of an Information Handling System (IHS), wherein the workspace has been instantiated by a workspace orchestration service executed on the IHS, wherein the one or more operating characteristics comprise at least one of: an input/output (I/O) device fault, an improper memory access request, or a page fault, and wherein the at least one hardware device comprises a Security Protocol and Data Model (SPDM)-enabled hardware device;

performing a mutual authentication procedure with the SPDM-enabled hardware device to form a SPDM-based trusted network between the SPDM-enabled hardware device and the BMC;

determining, using the instructions, that the one or more operating characteristics are indicative of a security breach of the fixed pass-through configuration, based at least in part on determining that at least one of the one or more operating characteristics represents an uncorrectable error; and

performing, using the instructions, an operation to quarantine the at least one SPDM-enabled hardware device when the fixed pass-through configuration is determined to possess the security breach by maintaining the quarantined at least one SPDM-enabled hardware device in a quarantine state until a firmware update procedure has been performed on the at least one SPDM-enabled hardware device.

8. The fixed pass-through monitoring method of claim 7 , further comprising performing the operation to quarantine the at least one hardware device by removing the SPDM-enabled hardware device from the SPDM-based trusted network.

9. The fixed pass-through monitoring method of claim 7 , further comprising performing the operation to quarantine the at least one hardware device by performing a device detach operation on the SPDM-enabled hardware device.

10. The fixed pass-through monitoring method of claim 7 , further comprising performing the operation to quarantine the at least one hardware device by setting an Advanced Configuration and Power Interface (ACPI) state of the SPDM-enabled hardware device to an off state.

11. An Information Handling System (IHS), comprising:

first and second Security Protocol and Data Model (SPDM)-enabled hardware devices, the first SPDM-enabled hardware device comprising instructions that are executable by at least one processor to:

monitor one or more operating characteristics of the second SPDM-enabled hardware device, to determine whether or not a fault comprising one or more operating characteristics has been occurring at a rate that exceeds a specified threshold, wherein the second SPDM-enabled hardware device is operating in a fixed pass-through configuration with a workspace, wherein the workspace has been instantiated by a workspace orchestration service executed on the IHS, and wherein the one or more operating characteristics comprise at least one of: an input/output (I/O) device fault, an improper memory access request, or a page fault;

perform a mutual authentication procedure with the second SPDM-enabled hardware device to form a SPDM-based trusted network between the second SPDM-enabled hardware device and the BMC;

determine that the operating characteristics are indicative of a security breach of the fixed pass-through configuration, wherein the determination is based at least in part on determining that at least one of the one or more operating characteristics represents an uncorrectable error, using error severity information obtained from an interface bus configured to be coupled with the second hardware device; and

perform an operation to quarantine the second SPDM-enabled hardware device when the fixed pass-through configuration is determined to possess the security breach by maintaining the quarantined second SPDM-enabled hardware device in a quarantine state until a firmware update procedure has been performed on the second SPDM-enabled hardware device.

12. The IHS of claim 11 , wherein the instructions are further executed to perform the operation to quarantine the second SPDM-enabled hardware device by at least one of removing the second SPDM-enabled hardware device from the SPDM-based trusted network, performing a device detach operation on the second SPDM-enabled hardware device, or by setting an Advanced Configuration and Power Interface (ACPI) state of the second SPDM-enabled hardware device to an off state.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2021
From: PONNURU, VISWANATH; BISA, RAMA RAO; MUGUNDA, CHANDRASEKHAR; RADHAKRISHNAN, VINEETH; RAHIMAN, SHINOSE ABDUL; RAMAIAH, DHARMA BHUSHAN; K, KRISHNAPRASAD
To: DELL PRODUCTS, L.P.
Reel/Frame 056934/0130 →
Priority Claims (1)
IN 202111030705 · Jul 8, 2021 · national
Continuity (1)
Related Publication 20230009470A1 · Jan 12, 2023
References Cited (4)
US 20140173600A1 · Ramakrishnan Nair · 2014 [cited by examiner]
US 20150268970A1 · Mudusuru · 2015 [cited by examiner]
US 20200143047A1 · Shivanna · 2020 [cited by examiner]
US 20210390179A1 · Hahn · 2021 [cited by examiner]