CONTROLLING ACCESS TO PERIPHERAL PORTS OF A HOST COMPUTER SYSTEM

DE102021108971B4Active Publication Date: 2026-07-16HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102021108971
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-07-21
Filing Date
2021-04-11
Publication Date
2026-07-16
Estimated Expiration
2041-04-11

AI Technical Summary

Technical Problem

Existing security measures for host computer systems are inadequate in preventing unauthorized access to peripheral ports, which can lead to the theft of sensitive data or introduction of malicious data through devices like USB ninja cables, and current software-based solutions are prone to tampering and resource consumption.

Method used

Implementing an integrated port management chip (IC) that communicates with peripheral hubs and a manageability controller to enforce security actions such as accepting, rejecting, or disabling peripheral devices based on predefined access control rules, operating independently of the host computer's operating system.

Benefits of technology

Effectively controls access to peripheral ports, preventing unauthorized data extraction and injection, while reducing resource consumption and maintaining system performance by operating even when the host computer is powered off.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A host computer system (102) comprising: a port management chip with integrated circuit, IC (122), a plurality of peripheral device hubs (120), and a manageability controller (118), wherein each hub of the plurality of peripheral device hubs (120) comprises at least one port (124), wherein the port management IC (122) comprises a machine-readable medium (304) storing program instructions, and a processing resource (202) operatively coupled to the machine-readable medium (304), wherein the processing resource (202) executes the program instructions to: receive initial data from the plurality of peripheral device hubs (120), the initial data comprising a plurality of device identifiers of an initial peripheral device (128) and a port identifier of the at least one port (124); and transmit the initial data to the management controller. (118) to transmit;to receive at least one security action from the manageability controller (118), wherein the at least one security action is determined by the manageability controller (118) based on a comparison of the first data with second data comprising a plurality of access control rules, wherein the at least one security action is associated with each access control rule, and wherein each access control rule has the port identifier of the at least one port (124) that is assigned to a plurality of predetermined device identifiers of a second peripheral device; and to implement the at least one security action on the at least one port (124).
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] Peripheral devices, such as a Universal Serial Bus (USB) device, can be connected to peripheral ports / connectors, such as a USB port, to establish a connection to a host computer system. The USB standard was developed to allow peripheral devices (or external devices) such as printers, scanners, keyboards, mice, modems, cameras, storage devices, etc., to connect to the host computer system via a 4-wire bus. USB connections can include a plug, a cable coupled to the plug, and / or a communication protocol used in the 4-wire bus to establish the connection, communication, and / or power supply between the host computer system, the peripheral ports, and the peripheral devices. List of characters

[0002] Several examples are described below with reference to the following illustrations. Fig.is an example data center environment comprising a host computer system, an external computer system and a peripheral device according to the embodiments of the present disclosure. Fig. is a block diagram representing an integrated circuit port management chip (IC) comprising a processing resource that is operationally coupled to a machine-readable medium that stores executable program instructions, in accordance with embodiments of the present disclosure. Fig. is a block diagram representing a processing resource and a machine-readable medium encoded with example instructions for processing data in an integrated port management circuit chip (IC) according to embodiments of the present disclosure. Fig.is a flowchart that represents a method for controlling access to one or more ports of a host computer system using a port management chip (IC) according to the embodiments of the present disclosure. Fig. is a flowchart that represents a method for determining at least one security action by a manageability controller according to embodiments of the present disclosure.

[0003] In the drawings, identical reference numbers may denote similar, but not necessarily identical, elements. An index number "N" appended to some of the reference numbers is merely to indicate a plurality and does not necessarily represent the same quantity for every reference number with such an index number "N". Furthermore, the use of a reference number without an index number, which is referenced elsewhere with an index number, may here represent a general reference to the corresponding plural elements, collectively or individually. In another example, an index number "I", "M", etc., may be used instead of the index number "N". The illustrations are not necessarily to scale, and the size of some parts may be exaggerated for better illustration of the example shown.Furthermore, the drawings provide examples and / or implementations that correspond to the description; however, the description is not limited to the examples and / or implementations shown in the drawings. DETAILED DESCRIPTION

[0004] The following detailed description refers to the accompanying drawings. Wherever possible, the same reference numbers are used in the drawings and the following description to refer to identical or similar parts. However, it is expressly understood that the drawings serve only for illustration and description. Although several examples are described in this document, modifications, adaptations, and other implementations are possible. Accordingly, the following detailed description does not limit the disclosed examples. Instead, the proper scope of the disclosed examples can be defined by the accompanying claims.

[0005] The terminology used here serves only to describe examples and is not intended to be restrictive. The singular forms "ein," "ein," and "die" used here also include the plural forms unless the context clearly indicates otherwise. The term "plural" as used here is defined as two or more than two. The term "ein Weitere," as used here, is defined as at least one second or more. The term "gekoppelt," as used herein, is defined as connected, either directly without any intervening elements or indirectly with at least one intervening element, unless otherwise specified. Two elements may be mechanically, electrically, or communicatively coupled via a communication channel, path, network, or system. The term "and / or," as used here, refers to and includes all possible combinations of one or more of the elements listed.It is also understood that, although the terms "first," "second," "third," etc., may be used here to describe different elements, these elements should not be restricted by these terms, since these terms are only used to distinguish one element from another unless otherwise stated or the context indicates otherwise. As used herein, the term "contains" means that it includes but is not limited; the term "including" means that it includes but is not limited; the term "based on" means at least partially based on.Furthermore, the terms "peripheral device" or "external device" as used here can refer to a type of electronic device that is not part of a host computer system, or that is an add-on device to the host computer system and may need to be connected to the host computer system by plugging or attaching it in order to input information to and receive information from the host computer system. Similarly, the term "peripheral port" can refer to a type of electronic connector that is either inherent to the host computer system or integrated into the host computer system and provides the ability to connect the peripheral device in order to input information to and receive information from the host computer system. In some examples, the peripheral device and the peripheral port may function like a plug and socket of the electronic device.Furthermore, the term "plug in" can refer to the physical insertion of the peripheral device into the peripheral port of the host computer system. However, the term "install" can also refer to the virtual addition of the peripheral device to the host computer system via a secure web console. Additionally, the term "host computer system" can refer to a computing node containing sensitive data, connected to a TCP / IP network, including the Internet, and hosting or running one or more customer workloads. Finally, the term "front end" can refer to a side of a host computer system that includes a display area to provide a user / administrator with easy access to frequently used devices of the host computer system, such as...a power switch, peripheral ports, and the display of other relevant information about the host computer system; ii) is easily visible to the user when mounted in a rack or enclosure of a data center; and iii) has one or more clamps for securing the host computer system to the rack or enclosure. Similarly, the term "rear" may refer to a side opposite the front of the host computer system that i) has rarely accessible ports, such as network and power connectors, for connecting the host computer system to the respective power supply unit; and ii) is hidden from the user / administrator when installed in the rack or enclosure. The term "peripheral side" may refer to a side of the host computer system that extends between the front and rear of the host computer system.

[0006] To illustrate the present disclosure, certain examples are given with reference to the information contained in the Fig. The components shown are described. However, the functionality of the components shown may overlap and may be present in a smaller or larger number of elements and components. Furthermore, all or part of the functionality of the elements shown may coexist or be distributed across multiple geographically dispersed locations. In addition, the disclosed examples can be implemented in various environments and are not limited to the examples shown. Furthermore, the functionality associated with Fig.The described sequence of operations is an example and is not intended to be limiting. Additional or fewer operations or combinations of operations may be used or varied without departing from the scope of the disclosed examples. Therefore, the present disclosure merely presents examples of implementations, and many variations and modifications to the described examples are possible. Such modifications and variations are intended to be included within the scope of this disclosure and are protected by the following claims.

[0007] This disclosure describes example implementations of a system and method for controlling access to one or more peripheral ports of a host computer system from a peripheral device. In some examples, the peripheral port may be a Universal Serial Bus (USB) port, and the peripheral device may be a USB device. It is noted that the terms "peripheral port," "peripheral connector," and "port" may be used interchangeably. Likewise, the terms "peripheral device" and "external device" may be used interchangeably. In one or more examples, the host computer system may include a port management chip (IC) that can act as a centralized port manager for the host computer system to control access from the peripheral device to the one or more peripheral ports belonging to each peripheral device hub (or USB hub) of the host computer system.When the peripheral device is connected or mounted to the peripheral port, the port management IC can receive data corresponding to the peripheral device and the peripheral port to which the peripheral device is connected or mounted. The port management IC can then forward the received data to a manageability controller of the host computer system and receive at least one security action from the manageability controller. Furthermore, the port management IC can implement the at least one security action directly at the peripheral port. In some examples, the at least one security action might include accepting the peripheral device, rejecting the peripheral device, or disabling the peripheral port.In one or more examples, the management controller can compare the received data with predefined data containing a variety of access control rules to determine the minimum security action and transmit the specified security action to the port management IC. Once the port management IC implements the minimum security action on the peripheral port to which the peripheral device is plugged in or mounted, the port management IC can then transfer control of that peripheral port, in accordance with the peripheral device, to the operating system (OS) of the host computer system until the peripheral device is unplugged or removed from the host computer system's peripheral port.

[0008] Data centers comprise computing systems such as server systems, storage systems, and various other types of computing systems that contain sensitive data. Typically, customers utilize at least some of the data center's computing systems to run workloads based on their business requirements. Accordingly, customers can invest significant amounts of time, effort, and money in securing these computer systems by identifying and remediating security vulnerabilities. However, security vulnerabilities created by unrestricted / unauthorized access to peripheral ports, such as a Universal Serial Bus (USB) port on the computer systems, through the use of peripheral devices like USB devices, can lead to the loss of sensitive data from the computer systems or the infiltration of malicious (harmful) data into the computer systems.

[0009] Current security measures and policies for protecting against unauthorized access to computer systems focus on what enters and leaves the data center. Often, certain data centers require user consent to conduct random or periodic scans before granting access. While this method is effective in preventing unauthorized USB devices from entering or leaving the data center, it is not foolproof and is not practical to implement. As long as the user has access to the computer systems within the data center, a USB device can be plugged into a USB port, and sensitive data can be stolen or malicious data can be introduced. More recently, another type of peripheral device, such as...A USB ninja cable, used to extract sensitive data from computer systems. In this case, the USB ninja cable had physical properties essentially similar to a normal USB cable, but when such a USB ninja cable is connected or plugged into the peripheral port, it can function as a virtual keyboard and send pre-programmed commands to the computer systems to extract or misuse sensitive data, or to introduce malicious data into the computer systems.

[0010] Therefore, it is crucial to prevent the extraction and misuse of sensitive data from computer systems, as well as the injection of malicious data into these systems. Even in cases where data extraction is authorized, copying sensitive data to peripheral devices can raise security concerns, as encryption alone may not be sufficient to protect such sensitive data during transmission. Furthermore, it is essential to prevent malicious data from entering the computer systems (intentionally or unintentionally) via peripheral devices.

[0011] Some existing methods for protecting USB ports rely on software-based port management devices. However, such software-based port management devices can be vulnerable to tampering, require administration and maintenance, consume computer system resources, and can also negatively impact the performance of applications or legitimate peripherals. Furthermore, there are no mechanisms to prevent unauthorized access to peripheral ports before the computer systems are even powered on.

[0012] One technical solution to the problems mentioned above may involve using an integrated port management chip (IC) of a host computer system to control access to each peripheral port of the host computer system from a peripheral device or an external device. In one or more examples, the port management IC may be communicatively connected to at least one peripheral port of each hub of a multitude of peripheral device hubs and to a management controller, such as a baseboard management controller (BMC) of the host computer system. When attached, for example,Upon plugging or mounting the peripheral device to the at least one peripheral port, the port management IC can negotiate with a corresponding peripheral hub (or multiple peripheral hubs) and the manageability controller and directly enforce or implement the at least one security action on the at least one peripheral port to control access to the at least one peripheral port from the peripheral device.

[0013] When a peripheral device is connected to the at least one peripheral port, the peripheral hub hosting the at least one peripheral port can, for example, receive initial data corresponding to the peripheral device and the at least one peripheral port to which the peripheral device is connected. In some examples, a microcontroller of the peripheral hub can receive the initial data from the first peripheral device and the at least one peripheral port. The port management IC can then receive the initial data from the corresponding peripheral hub and transmit the initial data to the manageability controller. The manageability controller can compare the initial data with a second set of data containing a variety of access control rules to determine at least one security action based on such comparisons of the initial and second sets of data.The manageability controller can then communicate the at least one security measure to the port management IC. In such examples, the port management IC can then implement the at least one security measure directly on the at least one peripheral port.

[0014] In some examples, the first set of data may contain a plurality of device identifiers of a first peripheral device and a port identifier of the at least one peripheral port. The second set of data may contain a plurality of access control rules, each access control rule associated with the at least one security action. In some examples, the at least one security action includes accepting the peripheral device, rejecting the peripheral device, and disabling the at least one peripheral port. In one or more examples, each access control rule may have at least one predetermined port identifier of the at least one peripheral port, which is mapped to a plurality of predetermined device identifiers of a second peripheral device.In some examples, the predefined port identifier of at least one peripheral port and the multiple predefined device identifiers of the second peripheral device are provided by an authorized user / administrator of the host computer system. It's worth noting that the authorized user can directly input / edit the second set of data into the manageability controller via a web console or RESTful commands. Since the manageability controller stores the access control rules, it can manage access to the virtual ports, and the port management IC chip can manage access to the physical ports.

[0015] In one or more examples, access control rules can be defined based on business requirements, and at least one security action is defined based on the type of peripheral device, such as a storage device, a camera device, or a human interface device like a keyboard, mouse, and the like. In some examples, the at least one peripheral port can be a physical port or a virtual port.

[0016] It can be noted here that the port management IC can operate in the background without affecting the functionality or operation of the host computer system's operating system (OS) and the applications running on the OS, until the peripheral device is accepted (or verified or approved) by the port management IC for use in the host computer system. In this way, the port management IC can isolate the operating system and other hardware of the host computer system from the peripheral device until it is released. Later, the port management IC can release the use of the peripheral device to the operating system until the peripheral device is unplugged or ejected from the host computer system's peripheral port.

[0017] Because the manageability controller can be powered via an auxiliary power rail, it can remain active even when the host computer system is powered off. This allows the manageability controller to determine the security action and have it implemented by the port management IC chip throughout the host computer system's lifecycle to control access to one or more peripheral ports from the peripheral device.

[0018] Fig.Figure 100 shows an exemplary data center environment in which a host computer system 102 is operationally coupled with an external computer system 104, such as a data center management system, for the secure management of workloads hosted on the host computer system 102. The exemplary data center environment 100 can be implemented as an enterprise system, a consumer system, or an industrial system. It facilitates the execution or operation of workloads to provide the intended service to end users and protects the workloads against one or more security vulnerabilities.

[0019] In some other examples, the data center environment 100 may contain infrastructure resources, such as a variety of host computer systems 102, each functionally connected to the external computer system 104. It can be noted here that the data center environment 100 may additionally contain a variety of other infrastructure resources, such as cooling devices, power and management devices, local hard drives, storage systems, storage area networks (SANs), network devices, network connections, network fabric, storage fabric, and the like. In such examples, the data center environment 100 may provide a cloud service for implementing the workloads of one or more customers by utilizing at least some of the identified infrastructure resources, depending on the business requirements of that one or more customers.In some examples, the example data center environment 100 may be owned by one or more customers, or by a provider, or a combination thereof.

[0020] An administrator 106 or a user (not shown) can access the external computer system 104 to regulate or manage the host computer system 102. It can be noted here that the administrator 106 may be a representative of the data center environment 100. In the example shown, the external computer system 104 is a server deployed in the data center environment 100. In some other examples, the external computer system 104 may be deployed outside the data center environment 100 without altering the scope of this disclosure. The external computer system 104 may provide a graphical user interface (GUI) or a web console 108 for the administrator 106 to securely interact with and manage the data center environment 100, such as the host computer system 102.In some other examples, the external computer system 104 can provide a command-line interface 110 for the administrator 106 to interact with and manage the host computer system 102.

[0021] The host computer system 102 is operationally connected to the external computer system 104 via a network 112. In such examples, the network 112 can be a TCP / IP network (Transmission Control Protocol / Internet Protocol), which is a set of communication protocols used to connect network devices on the Internet.

[0022] In some examples, the host computer system 102 is a server used in the data center environment 100 to host the workloads of one or more customers. In one or more examples, the host computer system 102 may include a central processing unit (CPU) 114, main memory 116, a manageability controller 118, a variety of peripheral hubs 120, and an integrated port management circuit (IC) 122.

[0023] The CPU 114 can be operationally coupled with the main memory 116 and execute one or more program instructions stored in the main memory 116 to run software of the host computer system 102, such as an operating system and workloads running on the operating system. It can be noted here that the operating system can perform all basic tasks such as file management, memory management, process management, input / output processing, and control of peripheral devices such as disk drives, printers, and the like. The workload can be a production workload, a development workload, or a test workload, depending on the customer's requirements. The workload may contain sensitive information or data that is protected for the customer.In some examples, the production workload might include running an ATM application program, a payroll application program, or performing live video analytics. Similarly, the development effort might include executing a set of processes and using programming tools to create a new application program or software product. Furthermore, the testing effort might include executing another set of processes and testing tools to test the new application program or software product.

[0024] The manageability controller 118 can be a service processor capable of monitoring the physical state of the host computer system 102 or other hardware devices using one or more sensors. In some examples, the manageability controller 118 is a baseboard management controller (BMC) embedded in a motherboard or mainboard (not shown) of the host computer system 102 being monitored. In such examples, the mainboard may also house the CPU 114. The manageability controller 118 can help the administrator 106 remotely monitor the host computer system 102 and other hardware devices, thereby reducing the operating costs of running the data center environment 100. The manageability controller 118 can have its own Internet Protocol (IP) address, which can be accessed via the secure web console 108 or the command-line interface 110.Furthermore, the manageability controller 118 can have its own memory and a memory-connected processor and execute one or more program instructions stored in memory to monitor the host computer system 102, regulate one or more infrastructure resources of the host computer system 102, and interact with the external computer system 104. The manageability controller 118 can also be powered via an auxiliary power rail (not shown) even when the host computer system 102 is powered off. In this way, the external computer system 104 can establish a secure connection with the manageability controller 118 at any time and maintain continuous interaction with the manageability controller 118 throughout the entire lifecycle of the host computer system 102.

[0025] In some examples, each hub of the plurality of peripheral hubs 120 can contain a plurality of peripheral ports 124. Each hub of the plurality of peripheral hubs 120 can also contain a microcontroller 126, which is communicatively connected to the plurality of peripheral ports 124 of the corresponding hub and to the port management IC 122. The microcontroller 126 can establish a connection with a first peripheral device 128 when it is physically connected to the at least one peripheral port 124 and negotiate with the first peripheral device 128 to obtain initial data corresponding to the first peripheral device 128 and the at least one peripheral port 124 to which the first peripheral device 128 is connected. In some examples, the microcontroller 126 can use standard USB protocols for negotiation with the variety of peripheral connectors 124 and the port management IC 122.

[0026] In the example of Fig.The multiple peripheral hubs 120 comprise a first peripheral hub 120A, which is coupled to a peripheral side 130 of the host computer system 102, a second peripheral hub 120B, which is coupled to a front side 132 of the host computer system 102, and a third peripheral hub 120C, which is coupled to a rear side 134 of the host computer system 102. Furthermore, the first peripheral hub 120A comprises two peripheral ports, for example, a first peripheral port 124A and a second peripheral port 124B, and a first microcontroller 126A, which is communicatively connected to the first and second peripheral ports 124A and 124B, respectively.Similarly, the second peripheral hub 120B contains three peripheral ports, for example, a third peripheral port 124C, a fourth peripheral port 124D, and a fifth peripheral port 124E, and a second microcontroller 126B that is communicatively coupled to the third, fourth, and fifth peripheral ports 124C, 124D, and 124E, respectively. The third peripheral hub 120C comprises two peripheral ports, for example, a sixth peripheral port 124F and a seventh peripheral port 124G, and a third microcontroller 126C that is communicatively coupled to the sixth and seventh peripheral ports 124F and 124G, respectively. In a non-restrictive example, the third peripheral hub 120C can also contain a virtual port 124H. In such examples, each of the multitude of peripheral ports 124 can contain a port identifier that is unique or unmistakable for the respective peripheral port.For example, the first peripheral port 124A can have a port identifier as "PP-1101", the second peripheral port 124B can have a port identifier as "PP-1102", the third peripheral port 124C can have a port identifier as "PP-2201", the fourth peripheral port 124D can have a port identifier as "PP-2202", the fifth peripheral port 124E can have a port identifier as "PP-2203", the sixth peripheral port 124F can have a port identifier as "PP-3301", and the seventh peripheral port 124G can have a port identifier as "PP-3302". In some examples, each of the multiple peripheral ports 124 can be a physical port. In one or more examples, each of the multiple peripheral hubs 120 is a Universal Serial Bus (USB) hub, and each of the multiple peripheral ports 124 is a USB port.The functionalities of the multiple peripheral hubs 120 and the multiple peripheral ports 124 are described in more detail below.

[0027] In one or more examples, the port management IC 122 can be a hardware module that is operationally connected to the mainboard of the host computer system 102. In such examples, the hardware module can be a processing resource (in Fig. (not shown) for implementing functionalities of the port management IC 122 by executing program instructions contained in a machine-readable medium (in Fig.(not shown) of the hardware module. The port management IC 122 can act as a centralized port manager for the host computer system 102 to control access to each of the multiple peripheral ports 124 belonging to the multiple peripheral hubs 120, from the first peripheral device 128. In other words, the port management IC 122 is communicatively coupled with the multiple peripheral hubs 120, the manageability controller 118, and the CPU 114 to centrally control access to each port of the multiple peripheral ports 124 from the first peripheral device 128. In some examples, the port management IC 122 can be coupled with the microcontroller 126 of each hub of the multiple peripheral hubs 120 to receive the initial data.Furthermore, the port management IC 122 can be coupled with the manageability controller 118 to transmit the initial data to the manageability controller 118 and to receive at least one security action from the manageability controller 118. The port management IC 122 can also be coupled with any of the multiple peripheral ports 124 to directly implement the at least one action on the corresponding peripheral port 124. In some examples, the security actions might include accepting the first peripheral device 128, rejecting the first peripheral device 128, and disabling at least one port 124. The functionalities of the port management IC 122 are described in more detail below.

[0028] In some examples, the example data center environment 100 might contain the first peripheral device 128, such as a USB device. The first peripheral device 128 might have a variety of first device identifiers associated with it. In some non-restrictive examples, the variety of first device identifiers might include a vendor identifier, a class description, and a subclass description. In one example, the vendor identifier might provide information about the vendor of the first peripheral device 128. It can be noted here that the vendor identifier is a standard identifier that is unique or distinctive for each vendor. For example, the vendor identifier for one vendor 'A' might be 'PD-AAA', for instance. Similarly, the vendor identifier for another vendor 'B' might be 'PD-BBB', and for yet another vendor 'C', 'PD-CCC'.Furthermore, the class description can specify a broad category to which the first peripheral device 128 belongs. For example, the class description for the first peripheral device 128 can be classified as "Human Interface Device," "Mass Storage Device," "Network Device," or "Vision Control Device," and so on, based on the type of the first peripheral device 128. It can be noted here that the class description can be standardized and unique or distinguishable across manufacturers. For example, the class description for the Human Interface Device can be categorized as "PD-HID." Similarly, the class description for the Mass Storage Device can be categorized as "PD-STO," for the Network Device as "PD-NET," and for the Vision Control Interface as "PD-VCI." Furthermore, each class description can be subdivided into subclass descriptions.For example, the class description of the human interface device "PD-HID" can be further subdivided, e.g., into "keyboard" or "mouse". In such examples, the subclass description for the keyboard could be, for example, "PD-KEY". Similarly, the subclass description for the mouse could be, for example, "PD-MOU".

[0029] The external computer system 104 can also include a plurality of peripheral ports 136. In some examples, each port of the plurality of peripheral ports 136 can be a USB port. In one or more examples, the first peripheral device 128 can also be connected to at least one peripheral port of the plurality of peripheral ports 136 of the external computer system 104 and mounted to the host computer system 102 via the virtual port 124H. The method for securely attaching the first peripheral device 128 to the host computer system 102 is described in more detail below.

[0030] During operation, the administrator 106 can securely log on to the host computer system 102 and store secondary data, including a variety of access control rules and security actions, in the manageability controller 118. If the secondary data is already stored in the manageability controller 118, the administrator 106 can update the access control rules and / or security actions based on business requirements. In some examples, the administrator 106 can access the web console 108 to store / update the secondary data in the manageability controller 118's memory. In other examples, the administrator 106 can use the command-line interface 110 to store / update the secondary data in the manageability controller 118's memory.In such examples, the administrator can use a RESTful (Representational State Transfer) command to save or update the second data via the command line interface 110.

[0031] An example of second data, containing the multitude of access control rules and security actions, can be shown as in Table 1 below. TABLE - 1 ACCESS CONTROL RULE NO. . ACCESS CONTROL RULES SAFETY MEASURES PERIPHERAL CONNECTION IDENTIFICATIONS A NUMBER OF SECOND IDENTIFICATIONS FOR PERIPHERAL DEVICES PROVIDER IDENTIFICATION CLASS DESCRIPTION SUBCLASS DESCRIPTION 1 PP-2201 OR PP-2202 OR PP-2203 PD-ANY PD-HID PD-KEY OR PD-MOU ACCEPT 2 PP-1101 OR PP-1102 PD-ANY PD-HID PD-KEY OR PD-MOU REJECT 3 PP-3301 OR PP-3202 PD-ANY PD-HID PD-KEY OR PD-MOU REJECT 4 PP-ALL PD-ANY PD-VCI PD-CAM SWITCH OFF, LOG 5 PP-2201 OR P3301 PD-AAA OR PD-BBB OR PD-CCC PD-STO PD-ANY ACCEPT 6 PP-2201 OR PP-2202 OR PP-2203 PD-ANY PD-STO PD-ANY REJECT 7 PP-2201 OR PP-2202 OR PP-2203 PD-ANY PD-NET PD-ANY REJECT 8 PP-1101 OR PP-1102 OR PP-3301 OR PP-3202 PD-BBB PD-STO OR PD-NET PD-ANY ACCEPT 9 PP-ALL PD-ANY PD-OUT PD-PRI ACCEPT

[0032] In the example shown, Example Table 1 has nine access control rules, each associated with at least one security action to regulate access to the multiple peripheral ports 124 of the host computer system 102. Referring to Table 1 below, each access control rule has at least one predetermined peripheral port identifier that is mapped to a plurality of predetermined device identifiers of a second peripheral device. Furthermore, each access control rule is associated with at least one security action. In some examples, the security actions may include accepting the first peripheral device 128, rejecting the first peripheral device 128, and disabling the at least one peripheral port 124.

[0033] Referring to the first access control rule in Table 1, the third, fourth, and fifth peripheral ports 124C, 124D, and 124E, respectively, belonging to the second peripheral hub 120B, are assigned to the second peripheral device, which is manufactured by "ANY" vendors representing the class description "Human Interface Device" and having the subclass descriptions "Keyboard" or "Mouse." In such an example, the first access control rule is linked to at least one security action as "Accepting" the first peripheral device 128.

[0034] In the second access control rule, the first and second peripheral ports 124A and 124B, respectively, belonging to the first peripheral hub 120A, are assigned to the second peripheral device, which is manufactured by "ANY" vendors, represents the class description "Human Interface Device," and has the subclass descriptions "Keyboard" or "Mouse." In this example, the second access control rule is linked to at least one security action as "Reject" of the first peripheral device 128.

[0035] In the third access control rule, the sixth and seventh peripheral ports 124F and 124G, respectively, belonging to the third peripheral hub 120C, are assigned to the second peripheral device, which is manufactured by "ANY" vendors, represents the class description "Human Interface Device," and has the subclass descriptions "Keyboard" or "Mouse." In this example, the third access control rule is linked to at least one security action as "Reject" of the first peripheral device 128.

[0036] In the fourth access control rule, the multiple peripheral ports 124 with the port identifier "PP-ALL" are assigned to the second peripheral device, which is manufactured by "ANY" vendors, has the class description "Visual Control Interface" and a subclass description "Camera". In such an example, the fourth access control rule is linked to at least one security action as "Disabling" peripheral port 124 and creates a "Log" entry about the security action implemented on peripheral port 124 in a log file (not shown) of the host computer system 102.

[0037] In the fifth access control rule, the third and sixth peripheral ports 124C and 124F, belonging to the second and third peripheral hubs 120B and 120C respectively, are assigned to the second peripheral device, which is manufactured by companies such as "A", "B", or "C", representing the class description "Mass Storage Device" and the subclass description "ANY". In this example, the fifth access control rule is linked to at least one security action as "Accept" for the first peripheral device 128.

[0038] In the sixth access control rule, the third, fourth, and fifth peripheral ports 124C, 124D, and 124E, respectively, belonging to the second peripheral hub 120B, are assigned to the second peripheral device, which is manufactured by "ANY" vendors, represents the class description "Mass Storage Device," and has the subclass description "ANY." In this example, the sixth access control rule is linked to at least one security action as "Reject" of the first peripheral device 128.

[0039] In the seventh access control rule, the third, fourth, and fifth peripheral ports 124C, 124D, and 124E, respectively, belonging to the second peripheral hub 120B, are assigned to the second peripheral device, which is manufactured by "ANY" vendors, represents the class description "Network Device," and has the subclass description "ANY." In this example, the seventh access control rule is linked to at least one security action as "Reject" of the first peripheral device 128.

[0040] In the eighth access control rule, the first, second, sixth, and seventh peripheral ports 124A, 123B, 124F, and 124G, respectively, belonging to the first and third peripheral hubs 120A and 120C, are assigned to the second peripheral device, which is manufactured by a vendor such as "B" and has a class description such as "Mass Storage Device or Network Device" and a subclass description "ANY". In this example, the eighth access control rule is linked to at least one security action as "Accept" for the first peripheral device 128.

[0041] In the ninth access control rule, the multitude of peripheral ports 124 with the port identifier "PP-ALL" is assigned to the second peripheral device, which is manufactured by "ANY" vendors, has the description "Output Class", and a subclass description "Printer". In this example, the ninth access control rule is linked to at least one security action as "Accept" of the first peripheral device 128.

[0042] In one or more examples, the administrator 106 of the data center environment 100 defines the multitude of access control rules and the corresponding security actions. In some examples, the administrator 106 may obtain necessary input / information from the one or more customers whose workloads are hosted on the host computer system 102 to formulate each of the multitude of access control rules. In other words, the at least one security action associated with each access control rule is determined based on the type of second peripheral device that the one or more customers have authorized for use in the data center environment 100. For example, the second peripheral device belonging to the class description "visual inspection interface" may represent a security threat (e.g., physical and digital security) to the data center environment 100.Accordingly, one or more customers may have instructed Administrator 106 to take strict measures against the use of this type of second peripheral device, thereby "disabling" peripheral port 124 by cutting off its power supply. It should be noted that when peripheral port 124 is disabled, it becomes completely inactive or unresponsive to future actions on that particular peripheral port until Administrator 106 intervenes and makes changes to the settings of peripheral port 124, for example, by turning it on to restore that particular peripheral port to an active state.

[0043] During operation or use, the administrator 106 or any user who has access to the data center environment 100 can, for example, physically connect the first peripheral device 128 to the host computer system 102 in order to either input information into the host computer system 102 or retrieve information from it.

[0044] In one example, the user can connect the first peripheral device 128 with manufacturer identification "PD-BBB", class description "PD-HID", and subclass description "PD-KEY" to the first peripheral port 124A with peripheral port identification "PP-1101". In such cases, when the first peripheral device 128 is plugged into the first peripheral port 124A, the first peripheral hub 120A can become active. The first microcontroller 126A, which belongs to the first peripheral hub 120A, can inform the port management IC 122 about the insertion of the first peripheral device 128 into the host computer system 102. Later, the first microcontroller 126A can negotiate with the first peripheral device 128 and the first peripheral connector 124A to obtain the first data including the peripheral connector identifier of the first peripheral connector 124A and the multiple device identifiers of the first peripheral device 128.In some examples, the first microcontroller 126A can use standard USB protocols to negotiate with the multiple peripheral ports 124 and the port management IC 122. In the present example, the peripheral port identifier can be "PP-1101" and the multiple device identifiers can be "PD-BBB", "PD-HID", and "PD-KEY". The port management IC 122 can then query the first microcontroller 126A to receive the initial data. Subsequently, the port management IC 122 can establish a secure connection with the manageability controller 118 and transmit the initial data to the manageability controller 118.

[0045] In some examples, the manageability controller 118 can compare the initial data received from the port management IC 122 with the subsequent data, which contains the majority of the access control rules stored in the manageability controller 118's memory, to determine at least one security action. In the present example, the manageability controller 118 can apply the second access control rule listed in Table 1 because the peripheral port identifier of the first peripheral port 124A and each of the multiple peripheral device identifiers of the first peripheral device 128 received from the initial data match the condition listed in the second access control rule in Table 1.For example, the port identifier, such as "PP-1101," of the first peripheral port 124A, and the multiple peripheral device identifiers, such as "PD-BBB," "PD-HID," and "PD-KEY," of the first peripheral device 128 match the predetermined peripheral port identifier, such as "PP-1101," and the multiple predetermined peripheral device identifiers, such as "PD-BBB," "PD-HID," and "PD-KEY," of the second peripheral device, as listed in the second access control rule of Table 1. Accordingly, the management controller 118 can select the one or more security actions associated with the second access control rule, such as "Reject" for the first peripheral device 128. Subsequently, the port management IC 122 can query the manageability controller 118 to obtain the one or more security actions selected by the manageability controller 118. B. “Reject” the first peripheral device 128.

[0046] The port management IC 122 can then interact directly with the first peripheral port 124A to implement the at least one security action selected by the manageability controller 118. In some examples, the port management IC 122 can use standard USB protocols to implement the at least one security action on the majority of the peripheral ports 124. In the present example, the port management IC 122 cannot establish a communication link with the first peripheral device 128 via the first peripheral port 124A to prevent the first peripheral device 128 from being detected and / or listed in the operating system (OS) interface for use by the user. It can be noted here that the port management IC 122 can perform all of the above functions in the background, i.e.,without interacting with the CPU 114 / the operating system of the host computer system 102, in order to isolate the operating system and other hardware of the host computer system 102 from the first peripheral device 128 until it is released / accepted for use.

[0047] In another example, the user can connect the first peripheral device 128, manufactured by an "ANY" vendor (i.e., with vendor identifier "PD-ANY"), class description "PD-HID", and subclass description "PD-MOU", to the third peripheral port 124C with peripheral port identifier "PP-2101". In such cases, when the first peripheral device 128 is plugged into the third peripheral port 124C, the second peripheral hub 120B can become active. The second microcontroller 126C, belonging to the second peripheral hub 120B, can inform the port management IC 122 about the insertion of the first peripheral device 128 into the host computer system 102.The second microcontroller 126C can negotiate with the first peripheral device 128 and the third peripheral port 124C to obtain initial data, including the peripheral port identifier of the third peripheral port 124C and the multiple device identifiers of the first peripheral device 128. In such examples, the peripheral port identifier might be "PP-2201," and the multiple device identifiers might be "PD-ANY," "PD-HID," and "PD-MOU." The port management IC 122 can then query the second microcontroller 126B to receive the initial data from it. Subsequently, the port management IC 122 can establish a secure connection with the manageability controller 118 and transmit the initial data to it.

[0048] In some examples, the manageability controller 118 can compare the initial data received from the port management IC 122 with the subsequent data, which contains the majority of the access control rules stored in the manageability controller 118's memory, to determine at least one security action. In such examples, the manageability controller 118 can apply the first access control rule listed in Table 1 because the peripheral port identifier of the third peripheral port 124C and each of the multiple peripheral device identifiers of the first peripheral device 128 received from the initial data match the condition listed in the first access control rule in Table 1.For example, the peripheral port identifier, such as "PP-2201" of the third peripheral port 124C, and each of the multiple peripheral device identifiers, such as "PD-ANY", "PD-HID", and "PD-MOU", of the first peripheral device 128, matches the predetermined peripheral port identifier "PP-2201" and each of the multiple predetermined peripheral device identifiers, such as "PD-ANY", "PD-HID", and "PD-MOU", of the second peripheral device, as listed in the second access control rule of Table -1. Accordingly, the management controller 118 can select the one or more security actions associated with the first access control rule, e.g., B. “Accept” the first peripheral device 128. Subsequently, the port management IC 122 can query the manageability controller 118 to obtain the at least one security action selected by the manageability controller 118, e.g., “Accept” the first peripheral device 128.

[0049] The port management IC 122 can then interact directly with the third peripheral port 124C to implement at least one security action selected by the management controller 118. In this example, the port management IC 122 can establish a communication link to the first peripheral device 128 via the third peripheral port 124C, allowing the first peripheral device 128 to be detected and / or listed in the operating system interface for user use. Later, the port management IC 122 can transfer the use of the first peripheral device 128 to the operating system until the first peripheral device 128 is unplugged or disconnected from the third peripheral port 124C. The aforementioned steps can be repeated if the user plugs or unplugs the first peripheral device 128 into the third peripheral port 124C as described here.

[0050] It can be noted here that the administrator 106 may have configured the access control rules such that the use of the first peripheral device 128, manufactured by any manufacturer and having the class description "Human Interface Device" and the subclass description "Keyboard" or "Mouse," is permitted when connected to one of the peripheral ports available on the front 132 of the host computer system 102. However, the first peripheral device 128 with the class description "Mass Storage Device" or "Network Device" will be rejected if plugged into one of the peripheral ports available on the side 130 or the rear 134 of the host computer system 102.

[0051] In certain other examples, the user can connect the first peripheral device 128, manufactured by "ANY" vendors (i.e., with vendor identifier "PD-ANY"), class description "PD-VCI", and subclass description "PD-CAM", to any of the multiple peripheral ports 124 (i.e., with peripheral port identifier "PP-ALL"). In such cases, when the first peripheral device 128 is plugged into one of the multiple peripheral ports 124, e.g., a fourth peripheral port 124D, a corresponding peripheral hub, e.g., the second peripheral hub 120B, can become active. The second microcontroller 126B, corresponding to the second peripheral hub 120B, can inform the port management IC 122 about the insertion of the first peripheral device 128 into the host computer system 102.The second microcontroller 126B can then negotiate with the first peripheral device 128 and the fourth peripheral port 124D to obtain the initial data, including the peripheral port identifier of the fourth peripheral port 124D and the multiple device identifiers of the first peripheral device 128. In such examples, the peripheral port identifier can be "PP-2202," and the multiple device identifiers can be "PD-ANY," "PD-VCI," and "PD-CAM." The port management IC 122 can subsequently query the second microcontroller 126B to receive the initial data from the second microcontroller 126B. The port management IC 122 can then establish a secure connection with the manageability controller 118 and transmit the initial data to the manageability controller 118.

[0052] In some examples, the manageability controller 118 can compare the initial data received from the port management IC 122 with the subsequent data, which contains the majority of the access control rules stored in the manageability controller 118's memory, to determine at least one security action. In such examples, the manageability controller 118 can apply the fourth access control rule listed in Table 1 because the peripheral port identifier of the fourth peripheral port 124D and each of the multiple peripheral device identifiers received from the initial data match the condition listed in the fourth access control rule in Table 1.For example, the peripheral port identifier, such as "PP-2202" or "PP-ANY" of the fourth peripheral port 124D, and each of the multiple peripheral device identifiers, such as "PD-ANY", "PD-VCI", and "PD-CAM" of the first peripheral device 128, matches the predetermined peripheral port identifier "PP-2202" or "PP-ANY" and each of the multiple predetermined peripheral device identifiers, such as "PD-ANY", "PD-VCI", and "PD-CAM" of the second peripheral device, as listed in the fourth access control rule of Table 1. Accordingly, the management controller 118 can select the security action associated with the fourth access control rule, such as "Disable" peripheral port 124 and "Log" the security action. The port management IC 122 can then query the manageability controller 118 to obtain the security action from the manageability controller 118, e.g.“Disabling” the fourth peripheral port 124D and “logging” the security action.

[0053] The port management IC 122 can then interact directly with the fourth peripheral port 124D to implement the security action selected by the manageability controller 118. In this example, the port management IC 122 can cut off the power supply to the fourth peripheral port 124D, so that the first peripheral device 128 is not detected and / or listed in the operating system interface for user use. Furthermore, the port management IC 122 can create a log entry about the security action implemented at peripheral port 124 in a log file (not shown) of the host computer system 102.It should be noted that if the fourth peripheral port 124D is disabled, it will become completely inactive or will not respond to future actions on that particular port until the administrator 106 changes the settings of that peripheral port 124 and turns the power back on to bring the fourth peripheral port 124D into the active state.

[0054] In some examples, the administrator 106 or another user can connect the first peripheral device 128 to one of the multiple peripheral ports 136 of the external computer system 104. Later, the user can attempt to connect the first peripheral device 128 to the host computer system 102 via virtual port 124H. For example, the user can access the web console 108 of the external computer system 104 and attempt to connect the first peripheral device 128, which is connected to the external computer system 104, to the host computer system 102 via virtual port 124H. In such examples, the manageability controller 118 can receive the initial data from the external computer system 104, corresponding to the multiple peripheral device identifiers of the first peripheral device 128 and the port identifier of peripheral port 136.For example, the port identifier of peripheral port 136 might be "PP-ALL", and the multiple peripheral device identifiers of the first peripheral device 128 might be "PD-ANY", "PD-OUT", and "PD-PRI". Then, the management controller 118 can compare the first set of data with the second set of data stored in the management controller 118 to determine at least one security action, as described above. Once the at least one security action is determined, the management controller 118 can implement such a security action on virtual port 124H of the host computer system 102.

[0055] In the present example, the peripheral port identifier is "PP-ALL," and the multiple peripheral device identifiers are "PP-ANY," "PP-OUT," and "PP-PRI." The first set of data matches the condition specified in the ninth access control rule of the second set of data (referring to Table 1). Accordingly, the manageability controller 118 can select at least one security action as "Accept" the first peripheral device 128 and implement at least one security action of connecting the first peripheral device 128 to the host computer system 102 via virtual port 124H.

[0056] In some examples, the port management IC 122 can also record in a log file the at least one security action implemented at the at least one peripheral port 124 when the first peripheral device 128 is plugged in or attached to the at least one peripheral port 124. In some examples, the log files can either be stored in the host computer system 102 and accessed by the administrator 106. In some other examples, the log files can be stored directly in the external computer system 104. It can be noted here that the administrator 106 can analyze the entries in the log files to determine any patterns of peripheral device usage in a particular peripheral port, or the maximum usage of a peripheral device manufactured by a specific manufacturer, and similar information.Later, the administrator can use the insights gained from the pattern analysis when formulating / revising / updating the access control rules.

[0057] Fig. is a block diagram of a computer system, e.g., a port management IC 222 with a processing resource 202 and a machine-readable medium 204 that stores executable program instructions. It should be noted here that the in Fig. the aforementioned port management IC is the same or similar to the one in Fig. The described port management IC 122 can be used. In the exemplary embodiment, the processing resource 202 is operationally coupled with the machine-readable medium 204.

[0058] The processing resource 202 can be a physical processor. In some examples, the physical processor can be at least one central processing unit (CPU), one graphics processing unit (GPU), one microprocessor, and / or other hardware devices used to perform the operations related to Fig. The described functionality is suitable. In some examples, the machine-readable medium 204 is non-transitory and is alternatively referred to as non-transitory machine-readable medium.

[0059] The processing resource 202 executes one or more program instructions to perform one or more of the operations in Fig.to execute the described functions. For example, the processing resource can execute 202 program instructions to receive initial data from the plurality of peripheral device hubs. In some examples, the initial data includes a plurality of device identifiers of a first peripheral device and a port identifier of the at least one peripheral port. In some examples, each hub of the plurality of peripheral device hubs is a USB (Universal Serial Bus) hub. Likewise, the peripheral device is a USB device, and the at least one peripheral port is a USB port.

[0060] The processing resource 202 can later transmit the first data received from the multiple peripheral hubs to a manageability controller. In some examples, the processing resource can execute the program instructions to establish a secure connection with the manageability controller before the first data is transmitted. Subsequently, the processing resource 202 can query the manageability controller to receive one or more security actions. In some examples, the security action(s) can include accepting the first peripheral, rejecting the first peripheral, or disabling one or more peripheral ports. In one or more examples, the security action is determined by the manageability controller based on a comparison of the first data with second data containing a variety of access control rules.In this example, the security action is associated with each access control rule, and each access control rule has the port identifier of at least one peripheral port, which is mapped to a plurality of predetermined device identifiers of a second peripheral device. The steps for determining the security action(s) by the administrative controller are described in conjunction with [reference to relevant section]. Fig. described.

[0061] The processing resource 202 can also execute the program instructions to directly implement the at least one security action on the at least one peripheral port, as in conjunction with Fig.described. In some examples, the processing resource 202 cannot establish the communication link with the peripheral device via the one or more peripheral ports to prevent the peripheral device 128 from being detected and / or listed in the operating system (OS) interface for use by the user. In some other examples, the processing resource 202 can establish the communication link with the peripheral device via the one or more peripheral ports. In certain other examples, the processing resource 202 can turn off the power supply to the one or more peripheral ports.

[0062] Fig.is a block diagram 300 that shows a processing resource 302 and a machine-readable medium 304 encoded with example instructions for processing data through an integrated port management circuit chip (IC). In some examples, the port management IC is used in an example environment 100 (as in Fig. (as shown) is operated to control access to at least one peripheral port of a host computer system from a peripheral device. It should be noted here that the in Fig. the mentioned port management IC is the same or similar to the one in Fig. or Fig.The described port management IC 122, 222 may be the machine-readable medium 304. This machine-readable medium is non-transitory and is alternatively referred to as non-transitory machine-readable medium. In some examples, the machine-readable medium 304 can be accessed by the processing resource 302. In some examples, the machine-readable medium 304 stores the program instructions corresponding to the functionality of a port management IC, as described in Fig. described.

[0063] The machine-readable medium 304 can be encoded with example commands 306, 308, 310, and 312. In some examples, an administrator of the host computer system can access a manageability controller of the host computer system and store / edit secondary data containing a variety of access control rules and security actions associated with each of the numerous access control rules.

[0064] When executed by the processing resource 302, instruction 306 can implement aspects of receiving initial data from a plurality of peripheral hubs. In some examples, the initial data includes a plurality of device identifiers of a first peripheral device and a port identifier of at least one peripheral port. A corresponding one of the plurality of peripheral hubs to which the peripheral port is connected can negotiate with the peripheral device and the at least one peripheral port to receive the initial data. In some examples, each hub of the plurality of peripheral hubs is a USB (Universal Serial Bus) hub. Similarly, the peripheral device is a USB device, and the at least one peripheral port is a USB port. The step of receiving the initial data from the plurality of peripheral hubs is described in Fig. described in detail.

[0065] When executed, instruction 308 can cause processing resource 302 to transmit the initial data received from the majority of peripheral hubs to the manageability controller, as described in Fig. described. In some examples, the port management IC's processing resource 302 can establish a secure connection with the manageability controller and transfer the initial data to the manageability controller.

[0066] When executed, command 310 can cause processing resource 302 to receive at least one security action from the manageability controller, as described in Fig. described. As in Fig.As described, the port management IC can query the manageability controller to receive the minimum security action. In some examples, the manageability controller can compare the first set of data with the second set of data to determine the minimum security action, as described in Fig. described.

[0067] Furthermore, instructions 312, when executed, can cause processing resource 302 to implement at least one security action on the at least one peripheral port, as shown in Fig.described. In some examples, the at least one security action may include accepting the peripheral device, rejecting the peripheral device, or disabling the at least one peripheral port. In some examples, the processing resource 302 may reject the peripheral device by not establishing a communication link with the peripheral device through the at least one peripheral port. Likewise, the processing resource 302 may accept the peripheral device by establishing a communication link with the peripheral device through the at least one peripheral port. In certain other examples, the processing resource 302 may disable the at least one peripheral port by turning off the power supply to the at least one peripheral port.

[0068] Fig.is a flowchart that illustrates Method 400 for controlling access to at least one peripheral port of a host computer system from a peripheral device according to embodiments of the present disclosure. It should be noted here that Method 400, in conjunction with Fig. is described.

[0069] Procedure 400 begins at block 402 and continues to block 404. In block 404, Procedure 400 involves receiving initial data from multiple peripheral hubs of a host computer system, as described in... Fig.As described. In one or more examples, a hub corresponding to the at least one peripheral port can negotiate with the peripheral device and the at least one peripheral port to obtain initial data when the peripheral device is connected (plugged in / mounted) to the at least one peripheral port of the host computer system. In some examples, the initial data can include a port identifier of the at least one peripheral port and the multiple device identifiers of the peripheral device. In some examples, each hub of the plurality of peripheral device hubs is a Universal Serial Bus (USB) hub. Likewise, the peripheral device is a USB device, and the at least one peripheral port is a USB port.

[0070] Procedure 400 continues to block 406. In block 406, procedure 400 involves transmitting the received initial data to a manageability controller of the host computer system, as described in Fig. described. In some examples, the port management IC can establish a secure connection with the manageability controller before the first data is transmitted to the manageability controller. In some examples, the manageability controller can be a Baseboard Management Controller (BMC). Procedure 400 continues in block 408.

[0071] In block 408, procedure 400 includes receiving at least one security action from the manageability controller, as described in Fig. described. In some examples, the port management IC can query the manageability controller to receive the at least one security action. In one or more examples, the at least one security action includes accepting the peripheral, rejecting the peripheral, or disabling the at least one peripheral port. The steps for determining the at least one security action are described in Fig.described and are described accordingly in the description Fig. explained. Procedure 400 continues to block 410.

[0072] In block 410, procedure 400 includes the direct implementation of the at least one security action on the at least one peripheral port, as in Fig. described. In some embodiments, the port management IC can reject the peripheral device by not establishing a communication link with the peripheral device via the at least one peripheral port. Likewise, the port management IC can accept the peripheral device by establishing a communication link with the peripheral device via the at least one peripheral connector. In certain other examples, the port management IC can disable the at least one peripheral connector by switching off the power supply to the at least one peripheral connector, as described in conjunction with Fig.It is described in detail. Procedure 400 ends in block 412.

[0073] Fig. is a flowchart that represents a Method 500 for determining at least one security measure by a manageability controller according to embodiments of the present disclosure. It should be noted here that the Method 500, in conjunction with the Fig. and Fig. is described.

[0074] Procedure 500 begins at block 502 and continues to block 504. In block 504, procedure 400 involves receiving initial data from a port management IC, as shown in Fig. and Fig. described. In one or more examples, the initial data can contain a port identifier of the at least one peripheral port and the multiple device identifiers of the peripheral device.

[0075] Procedure 500 continues to Block 506. In Block 506, Procedure 500 involves receiving second data, containing a variety of access control rules, from an administrator of a data center environment with a host computer system and an external computer system. In some examples, the administrator can access the host computer system's manageability controller either through a secure web console or a command-line interface and store / edit the second data, containing a variety of access control rules and security actions associated with each of those rules, in a store on the manageability controller. In some examples, the administrator can use a RESTful command to store / edit the access control rules in the manageability controller. As described in Fig.As explained, at least one security action is associated with each access control rule, and each access control rule has the port identifier of the at least one peripheral port, which is mapped to a plurality of predetermined device identifiers of a second peripheral device. Procedure 500 is continued further in Block 508.

[0076] In Block 508, Procedure 500 includes the determination of at least one security action by the manageability controller, as in Fig.As described, in some examples, the manageability controller can compare the first data with the second data to determine the at least one security measure. In one or more examples, the manageability controller can first compare the port identifier of the at least one peripheral port received in the first data with the at least one predetermined port identifier of the at least one peripheral port stored in the second data. If a match is found, the manageability controller can only shortlist those access control rules that have identical peripheral port identifiers and compare the multiple device identifiers of the peripheral device received in the first data with the multiple predetermined device identifiers of a second peripheral device stored in the second data.The administrative controller can then determine the access control rules if the conditions between the first and second data match and if at least one security action is associated with the determined access control rule. Procedure 500 continues to Block 510.

[0077] In block 510, procedure 500 includes the transmission of at least one security action to the port management IC, as described in Fig.As described. In some examples, the port management IC can query the manageability controller to receive the at least one security action. In one or more examples, the at least one security action includes accepting the peripheral, rejecting the peripheral, or disabling the at least one peripheral port. In some embodiments, the port management IC implements the at least one security action determined by the manageability controller. For example, the port management IC can reject the peripheral by not establishing a communication link with the peripheral through the at least one peripheral port. Likewise, the port management IC can accept the peripheral by establishing a communication link with the peripheral through the at least one peripheral port.In certain other examples, the port management IC can disable the at least one peripheral port by switching off the power supply to the at least one peripheral port, as in conjunction with . Fig. It is described in detail. Procedure 500 ends in block 512.

[0078] Various functions, such as those shown in the examples described here, can be implemented to address security vulnerabilities caused by unrestricted / unauthorized access to peripheral ports of the host computer system using a peripheral device, thereby preventing the theft of sensitive data from the host computer systems or the introduction of malicious (harmful) data into the host computer systems.

[0079] The foregoing description includes numerous details to facilitate an understanding of the subject matter disclosed herein. However, the implementation can also be carried out without some or all of these details. Other implementations may include modifications, combinations, and variations of the details described above. The following claims are intended to cover such modifications and variations.

Claims

[1] A host computer system comprising the following: a port management chip (IC) with integrated circuitry, a plurality of peripheral hubs and a manageability controller, wherein each hub of the plurality of peripheral hubs comprises at least one port, wherein the port management IC comprises a machine-readable medium that stores program instructions and a processing resource that is operationally coupled to the machine-readable medium, wherein the processing resource executes the program instructions to: Receiving initial data from the plurality of peripheral device hubs, wherein the initial data comprises a plurality of device identifiers of a first peripheral device and a port identifier of the at least one port; to transmit the initial data to the administrative controller; Receiving at least one security action from the manageability controller, wherein the at least one security action is determined by the manageability controller based on a comparison of the first data with second data comprising a plurality of access control rules, wherein the at least one security action is associated with each access control rule, and wherein each access control rule has the port identifier of the at least one port mapped to a plurality of predetermined device identifiers of a second peripheral device; and to implement at least one security action on at least one port. [2] The host computer system according to claim 1, wherein the at least one security action comprises at least one of the following: accepting the first peripheral device, rejecting the first peripheral device or disabling the at least one port. [3] The host computer system according to claim 1, wherein a hub from the plurality of peripheral device hubs is to receive the first data when the first peripheral device is plugged in or mounted to the at least one port belonging to the hub. [4] The host computer system according to claim 1, wherein the processing resource further executes the program instructions to log in a log file the at least one security action that was implemented at the at least one port when the first peripheral device is plugged in or attached to the at least one port. [5] The host computer system according to claim 1, wherein the at least one security action associated with each access control rule is determined based on a type of the second peripheral device. [6] The host computer system according to claim 1, wherein the at least one port comprises either a physical port or a virtual port. [7] The host computer system according to claim 1, wherein the first and second peripheral devices comprise a USB (Universal Serial Bus) device. [8] The host computer system according to claim 1, wherein the at least one port comprises a USB (Universal Serial Bus) port. [9] The host computer system according to claim 1, wherein the multiple predefined device identifiers comprise a manufacturer identifier of the second peripheral device, a class description of the second peripheral device and a subclass description of the second peripheral device. [10] A procedure comprising the following: Receiving initial data from a plurality of peripheral device hubs by a port management chip (IC) of a host computer system, wherein the initial data includes a plurality of device identifiers of an initial peripheral device and a port identifier of at least one port; Transmission of the first data by the port management IC to the manageability controller of the host computer system; Receiving at least one security action from the manageability controller by the port management IC, wherein the at least one security action is determined by the manageability controller based on a comparison of the first data with second data comprising a plurality of access control rules, wherein the at least one security action is associated with each access control rule, wherein each access control rule has the port identifier of the at least one port mapped to a plurality of predetermined device identifiers of a second peripheral device, and wherein the manageability controller and the port management IC are discrete components; and Implementation of at least one security action on at least one port by the port management IC. [11] The method according to claim 10, wherein the at least one safety action comprises at least one of the following elements: Accepting the first peripheral device, rejecting the first peripheral device, or disabling at least one port. [12] The method according to claim 10, further comprising that a hub of the multiple peripheral device hubs receives the first data when the first peripheral device is plugged in or attached to the at least one port belonging to the hub. [13] The method according to claim 10, which further comprises the port management IC logging in a log file the at least one security action that was implemented on the at least one port when the first peripheral device is plugged in or attached to the at least one port. [14] The method according to claim 10, wherein the at least one security action associated with each access control rule is determined based on a type of the second peripheral device. [15] The method according to claim 10, wherein the at least one port comprises either a physical port or a virtual port. [16] The method according to claim 10, wherein the first peripheral device and the second peripheral device comprise a Universal Serial Bus (USB) device and wherein the at least one port comprises a Universal Serial Bus (USB) port. [17] The method according to claim 10, further comprising one or more of the following steps: receiving or updating the second data by the manageability controller via a web console of the manageability controller or via a RESTful (Representational State Transfer) command. [18] The method according to claim 10, wherein the plurality of predefined device identifiers comprises a manufacturer identifier of the second peripheral device, a class description of the second peripheral device and a subclass description of the second peripheral device. [19] A non-transitory machine-readable medium that stores instructions that can be executed by a processing resource of a port management chip (IC), wherein the instructions include: Instructions to receive initial data from a plurality of peripheral device hubs, wherein the initial data includes a plurality of device identifiers of a first peripheral device and a port identifier of at least one port; Instructions to transmit the initial data to a manageability controller of the host computer system; Instruction to receive at least one security action from the manageability controller, wherein the at least one security action is determined by the manageability controller based on a comparison of the first data with second data comprising a plurality of access control rules, wherein the at least one security action is associated with each access control rule, wherein each access control rule has the port identifier of the at least one port mapped to a plurality of predetermined device identifiers of a second peripheral device, and wherein the manageability controller and the port management IC are discrete components; and Instructions for implementing at least one security action on at least one port. [20] The non-transitory machine-readable medium according to claim 19, wherein the at least one security action comprises at least one of the following actions: accepting the first peripheral device, rejecting the first peripheral device and locking the at least one port.

Citation Information

Patent Citations

  • Device authentication using list of known good devices

    US20140196142A1

  • Methods and apparatus to generate and update fibre channel firewall filter rules using address prefixes

    US8364852B1

  • Data transmission method, electronic equipment, USB equipment and storage medium

    WO2015188586A1