Dynamic unlocking of software defined silicon (SDSi) processor features via security protocol data model (SPDM)
In one embodiment, an Information Handling System (IHS), comprises an SPDM-enabled device conforming to a SPDM specification. The SPDM-enabled device causes the IHS to identify a device in the IHS having optional hardware features, provision activation data for the optional hardware features, and activate the optional hardware features by sending SPDM messages to the device. The IHS comprises a host processor module configured to host one or more processors, a secure control module configured to host a baseboard management controller, and a secure control interface configured to support communication between the secure control module and the host processor module. The one or more processors have optional hardware features. The one or more processors may be Software Defined Silicon (SDSi) devices. The baseboard management controller identifies the device having optional hardware features using a SPDM GET_CERTIFICATE request message sent to the devices.
1 . An Information Handling System (IHS), comprising:
a Security Protocol and Data Model (SPDM)-enabled device in conformance to a SPDM specification, wherein the SPDM-enabled device comprises at least one processor coupled to at least one memory, the at least one memory configured with program instructions stored thereon that, upon execution by the at least one processor, cause the IHS to:
identify a Software Defined Silicon (SDSi) device in the IHS configured with optional hardware features based at least in part on an encrypted capability activation payload and authentication certificate indexed against a hardware identity of the SPDM-enabled device;
provision activation data for the optional hardware features, wherein the activation data includes a capability activation payload and an authentication key certificate; and
activate the optional hardware features by sending SPDM messages to the SDSi device.
2 . The IHS of claim 1 , further comprising:
a host processor module configured to host one or more processors;
a secure control module configured to host a baseboard management controller; and
a secure control interface configured to support communication between the secure control module and the host processor module.
3 . The IHS of claim 1 , wherein the IHS is configured to expose a user interface to provision activation data for the optional hardware features.
4 . The IHS of claim 1 , wherein the IHS further comprises:
a credential vault configured to store the capability activation payload and authentication key certificate for a selected device hardware identity.
5 . The IHS of claim 2 , wherein the one or more processors are SDSi devices that have optional hardware features.
6 . The IHS of claim 2 , wherein the baseboard management controller is configured to identify the SDSi device with optional hardware features based at least in part on a SPDM GET_CERTIFICATE request message sent to the device.
7 . The IHS of claim 2 , wherein the baseboard management controller activates the optional hardware features by sending SPDM SET_CERTIFICATE/ENCAPSULATED_REQUEST messages to the SDSi device.
8 . The IHS of claim 3 , wherein the user interface is a Redfish API.
9 . The IHS of claim 4 , wherein the IHS is further configured to:
determine what optional hardware features to activate based upon a data center license; and
activate the optional hardware features using the capability activation payload and the authentication key certificate stored in the credential vault.
10 . A method for unlocking optional hardware features for an Information Handling System (IHS), the method comprising:
discovering Software Defined Silicon (SDSi) hardware devices with optional features via Security Protocol and Data Model (SPDM) messages sent by a baseboard management controller;
identifying optional features that are locked on the SDSi hardware devices, based at least in part on at least one encrypted capability activation payload and authentication certificate indexed against at least one respective identity of the SDSi hardware devices;
exposing a user interface to provision a capability activation payload and an authentication key certificate for the optional features; and
activating the optional features using the capability activation payload and the authentication key certificate by sending SPDM messages to the SDSi hardware devices.
11 . The method of claim 10 , wherein the baseboard management controller sends SPDM GET_VERSION and GET_CAPABILITIES request messages to discover SDSi hardware devices with optional features.
12 . The method of claim 10 , wherein locked optional features are identified from a hardware identity certificate obtained using an SPDM GET_CERTIFICATE request message.
13 . The method of claim 10 , wherein the optional features are activated by sending SPDM SET_CERTIFICATE/ENCAPSULATED_REQUEST messages to the SDSi hardware device.
14 . The method of claim 10 , further comprising:
encrypting and storing the at least one capability activation payload and authentication key certificate indexed against the at least one respective identity of the SDSi hardware devices in a credential vault.
15 . The method of claim 10 , further comprising:
performing a compatibility check between available hardware features and activated hardware features in the IHS;
identifying mismatches between available and activated hardware features; and
suggesting, to an IHS user, a proposed combination of hardware features to be activated for best system utilization.
16 . The method of claim 10 , further comprising:
identifying available optional hardware features in the IHS; and
determining a least feature set of optional features to be activated based on a current IHS configuration.
17 . The method of claim 10 , further comprising:
activating optional hardware features required by a current IHS license by provisioning the capability activation payload and the authentication key certificate via SPDM SET_CERTIFICATE/ENCAPSULATED_REQUEST messages.
18 . The method of claim 14 , further comprising:
identifying a system hardware configuration for the IHS; and
activating the optional features automatically based on the system hardware configuration using the capability activation payload and the authentication key certificate stored in the credential vault.