US 12,407,721 B2
Workspace-based fixed pass-through monitoring system and method for hardware devices using a baseboard management controller (BMC)
Viswanath Ponnuru, Bangalore (IN); Rama Rao Bisa, Bangalore (IN); Chandrasekhar Mugunda, Austin, TX (US); Vineeth Radhakrishnan, Bangalore (IN); Shinose Abdul Rahiman, Bangalore (IN); Dharma Bhushan Ramaiah, Bengaluru (IN); and Krishnaprasad K, Bengaluru (IN)
Assigned to Dell Products, L.P., Round Rock, TX (US)
Filed by Dell Products, L.P., Round Rock, TX (US)
Filed on Jul. 21, 2021, as Appl. No. 17/381,641.
Claims priority of application No. 202111030705 (IN), filed on Jul. 8, 2021.
Prior Publication US 2023/0009470 A1, Jan. 12, 2023
Int. Cl. H04L 9/30 (2006.01); G06F 11/14 (2006.01); H04L 9/40 (2022.01); H04L 29/06 (2006.01)
CPC H04L 63/1466 (2013.01) [G06F 11/141 (2013.01); H04L 63/0218 (2013.01); G06F 2201/86 (2013.01)] 12 Claims
OG exemplary drawing
 
1. An Information Handling System (IHS), comprising:
a plurality of hardware devices; and
a Baseboard Management Controller (BMC) in communication with the plurality of hard ware devices, the BMC comprising instructions that are executable by at least one processor to:
monitor one or more operating characteristics of at least one hardware device of the plurality of hardware devices to determine whether or not a fault comprising the one or more operating characteristics has been occurring at a rate that exceeds a specified threshold, wherein the at least one hardware device is operating in a fixed pass-through configuration with a workspace, wherein the workspace has been instantiated by a workspace orchestration service executed on the IHS, and wherein the one or more operating characteristics comprise at least one of: an input/output (I/O) device fault, a correctable error, an uncorrectable error, an improper memory access request, or a page fault, and wherein the at least one hardware device comprises a Security Protocol and Data Model (SPDM)-enabled hardware device;
perform a mutual authentication procedure with the SPDM-enabled hardware device to form a SPDM-based trusted network between the SPDM-enabled hardware device and the BMC;
determine that the operating characteristics are indicative of a security breach of the fixed pass-through configuration; and
perform an operation to quarantine the at least one SPDM-enabled hardware device when the fixed pass-through configuration is determined to possess the security breach by maintaining the quarantined at least one SPDM-enabled hardware device in a quarantine state until a firmware update procedure has been performed on the at least one SPDM-enabled hardware device.