skip to main content
research-article
Open access

Opening up the baseboard management controller

Published: 22 January 2020 Publication History

Abstract

If the CPU is the brain of the board, the BMC is the brain stem.

References

[1]
Common Vulnerabilities and Exposures. CVE-2019-6260; https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6260.
[2]
Common Vulnerabilities and Exposures. Intelligent Platform Management Interface; https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=ipmi.
[3]
Eclypsium. Virtual media vulnerability in BMC opens servers to remote attack; http://bit.ly/2NSdX2b
[4]
Fang, T. Introducing 'OpenBMC:' An open software framework for next-generation system management. Facebook Engineering, 2015; http://bit.ly/2PHS73T
[5]
Frazelle, J. Open-source firmware. acmqueue 17, 3 (2019); https://queue.acm.org/detail.cfm?id=3349301.
[6]
Heiliger, J. Building efficient data centers with the Open Compute Project. Facebook, 2011; http://bit.ly/2NBDwEm
[7]
Hudson, T. 2019. Modchips of the State; https://trmm.net/Modchips#Defenses.
[8]
Shobe, E., Mednick, J. RunBMC: OCP hardware spec solves data center BMC pain points; https://blogs.dropbox.com/tech/2019/03/runbmc-ocp-hardware-spec-solves-data-center-bmc-pain-points/
[9]
Sullivan, A. OpenPOWER & Open Compute: Full speed ahead with Barreleye, 2015; https://blog.rackspace.com/openpower-open-compute-barreleye.

Cited By

View all
  • (2024)Removing obstacles before breaking through the memory wallProceedings of the 2024 USENIX Conference on Usenix Annual Technical Conference10.5555/3691992.3692044(851-867)Online publication date: 10-Jul-2024
  • (2024)Verified Fault Handling for Modern Board Management ControllersFormal Aspects of Component Software10.1007/978-3-031-71261-6_2(21-38)Online publication date: 9-Sep-2024
  • (2023)Rethinking system audit architectures for high event coverage and synchronous log availabilityProceedings of the 32nd USENIX Conference on Security Symposium10.5555/3620237.3620260(391-408)Online publication date: 9-Aug-2023
  • Show More Cited By

Index Terms

  1. Opening up the baseboard management controller

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image Communications of the ACM
    Communications of the ACM  Volume 63, Issue 2
    February 2020
    80 pages
    ISSN:0001-0782
    EISSN:1557-7317
    DOI:10.1145/3380852
    Issue’s Table of Contents
    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 22 January 2020
    Published in CACM Volume 63, Issue 2

    Check for updates

    Qualifiers

    • Research-article
    • Popular
    • Refereed

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)1,245
    • Downloads (Last 6 weeks)97
    Reflects downloads up to 20 Jan 2025

    Other Metrics

    Citations

    Cited By

    View all
    • (2024)Removing obstacles before breaking through the memory wallProceedings of the 2024 USENIX Conference on Usenix Annual Technical Conference10.5555/3691992.3692044(851-867)Online publication date: 10-Jul-2024
    • (2024)Verified Fault Handling for Modern Board Management ControllersFormal Aspects of Component Software10.1007/978-3-031-71261-6_2(21-38)Online publication date: 9-Sep-2024
    • (2023)Rethinking system audit architectures for high event coverage and synchronous log availabilityProceedings of the 32nd USENIX Conference on Security Symposium10.5555/3620237.3620260(391-408)Online publication date: 9-Aug-2023
    • (2023)ATCA Multi-Node Management System Protocol OptimizationIntegrated Ferroelectrics10.1080/10584587.2023.2192679237:1(310-320)Online publication date: 10-Sep-2023
    • (2022)HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit Device2022 IEEE Symposium on Security and Privacy (SP)10.1109/SP46214.2022.9833745(1791-1807)Online publication date: May-2022
    • (2022)A Secure and Efficient USB-based In-band Communication Interface between Host and BMC2022 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA/BDCloud/SocialCom/SustainCom)10.1109/ISPA-BDCloud-SocialCom-SustainCom57177.2022.00036(228-237)Online publication date: Dec-2022
    • (2022)Hibernation Based Hybrid Booting for Baseboard Management Controller2022 International Conference on Computational Science and Computational Intelligence (CSCI)10.1109/CSCI58124.2022.00107(569-571)Online publication date: Dec-2022
    • (2022)NASCENT: A Non-Invasive Solution for Detecting Utilization of Servers in Bare-Metal CloudIEEE Access10.1109/ACCESS.2022.314595510(12866-12881)Online publication date: 2022
    • (2021)On malicious implants in PCBs throughout the supply chainIntegration10.1016/j.vlsi.2021.03.00279(12-22)Online publication date: Jul-2021
    • (2020)Framework for Managing Servers or Cluster of Servers & hardware Controlled by Raspberry pi or Servers2020 IEEE International Conference for Innovation in Technology (INOCON)10.1109/INOCON50539.2020.9298324(1-7)Online publication date: 6-Nov-2020

    View Options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Digital Edition

    View this article in digital edition.

    Digital Edition

    Magazine Site

    View this article on the magazine site (external)

    Magazine Site

    Login options

    Full Access

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media