Distributed secure communication system

By using a distributed secure communication engine to identify and sign the SCP subsystem, the problem of duplicate authentication between server devices in the information processing system is solved, and the efficiency of secure communication is improved.

CN116264861BActive Publication Date: 2025-10-28DELL PROD LP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202180066374.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-10-26
Filing Date
2021-04-28
Publication Date
2025-10-28
Estimated Expiration
2041-04-28

AI Technical Summary

Technical Problem

Existing information processing systems require time-consuming and repetitive authentication operations when establishing secure communication channels between server devices, resulting in low communication efficiency.

Method used

A distributed secure communication engine is adopted, which identifies the second system control processor (SCP) subsystem and uses a private key to sign the authentication communication to establish a secure communication channel and reduce redundant authentication operations.

Benefits of technology

It improves the efficiency of secure communication between information processing systems, reduces unnecessary authentication steps, and enables faster establishment of secure communication channels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116264861B_ABST
    Figure CN116264861B_ABST
Patent Text Reader

Abstract

A distributed secure communication system includes a first system control processor (SCP) subsystem coupled to a second SCP subsystem and a third SCP subsystem via a network. The first SCP subsystem identifies the second SCP subsystem, signs a first SCP authentication communication using a first private key to provide a first signed SCP authentication communication, and transmits the first signed SCP authentication communication to the second SCP subsystem. The first SCP subsystem receives the second signed SCP authentication communication from the second SCP subsystem, authenticates the second signed SCP authentication communication using a second public key associated with the second SCP subsystem, and, in response, establishes a first secure communication channel with the second SCP subsystem. The first SCP subsystem then receives proof of authentication of the third SCP subsystem from the second SCP subsystem and, in response, establishes a second secure communication channel with the third SCP subsystem without transmitting the signed SCP authentication communication.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] This disclosure relates in general to information processing systems, and more specifically to providing secure communication between information processing systems in a distributed manner.

[0002] As the value and use of information continue to increase, individuals and businesses are seeking alternative ways to process and store information. One option available to users is an information processing system. Information processing systems typically process, compile, store, and / or communicate information or data for business, personal, or other purposes, allowing users to leverage the value of information. Because technologies and information processing needs and requirements can vary between different users or applications, information processing systems can also vary in the following aspects: what information is processed, how it is processed, how much information is processed, stored, or communicated, and the speed and efficiency of processing, storing, or communicating information. Variations in information processing systems allow them to be general-purpose or configured for specific users or purposes (such as financial transaction processing, flight booking, enterprise data storage, or global communications). Furthermore, information processing systems can include a variety of hardware and software components that can be configured to process, store, and communicate information, and can include one or more computer systems, data storage systems, and networking systems.

[0003] Information processing systems (such as server devices and / or other computing systems known in the art) can be configured to communicate with each other via secure communication channels. For example, a baseboard management controller (BMC) subsystem in a server device (e.g., available from Round Rock, Texas, USA) The integrated server equipment provided by the joint-stock company The remote access controller (iDRAC) subsystem is operable to configure a secure communication channel between itself for secure data exchange. However, such conventional secure communication channel configuration systems require the BMC subsystems in any two server devices that will exchange secure communication with each other to perform authentication operations before the secure communication channel between the two server devices is established. This is time-consuming, only deals with the communication channel between the two subsystem devices, and has been found by the inventors of this disclosure to result in unnecessary and repetitive authentication operations.

[0004] Therefore, it is desirable to provide a secure communication system that solves the problems discussed above. Summary of the Invention

[0005] According to one embodiment, an Information Processing System (IHS) includes: a processing system; and a memory system coupled to the processing system and including instructions that, when executed by the processing system, cause the processing system to provide a distributed secure communication engine, the distributed secure communication engine being configured to: identify a second system control processor (SCP) subsystem and, in response, sign a first SCP authentication communication with a first private key to provide a first signed SCP authentication communication; transmit the first signed SCP authentication communication to the second SCP subsystem; receive a second signed SCP authentication communication from the second SCP subsystem and, in response, authenticate the second signed SCP authentication communication using a second public key associated with the second SCP subsystem; establish a first secure communication channel with the second SCP subsystem in response to authenticating the second signed SCP authentication communication; and receive proof of authentication for a third SCP subsystem from the second SCP subsystem and, in response, establish a second secure communication channel with the third SCP subsystem without transmitting the signed SCP authentication communication. Attached Figure Description

[0006] Figure 1 This is a schematic diagram illustrating an implementation scheme for an Information Processing System (IHS).

[0007] Figure 2 This is a schematic diagram illustrating an implementation scheme for a networked system.

[0008] Figure 3A This is a schematic diagram illustrating an implementation scheme of a computing system, which may include... Figure 2 In networked systems, and the distributed secure communication system disclosed herein can be utilized.

[0009] Figure 3B This is a schematic diagram illustrating an implementation scheme of a computing system, which may include... Figure 2 In networked systems, and the distributed secure communication system disclosed herein can be utilized.

[0010] Figure 4 This is a schematic diagram illustrating an implementation scheme of the SCP subsystem, which may include... Figure 3A or Figure 3B The distributed secure communication system disclosed herein can be provided in computing devices.

[0011] Figure 5A This is a flowchart illustrating an implementation of a method for providing distributed secure communication.

[0012] Figure 5B This is a flowchart illustrating an implementation of a method for providing distributed secure communication.

[0013] Figure 6A This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0014] Figure 6B This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0015] Figure 6C This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0016] Figure 6D This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0017] Figure 6E This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0018] Figure 6F This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5.

[0019] Figure 6G This illustrates the computing system 300 shown in Figure 3. Figure 2 A schematic diagram of an implementation scheme for a networked system, wherein the computing system has Figure 4 The SCP subsystem operates during the method shown in Figure 5. Detailed Implementation

[0020] For the purposes of this disclosure, an information processing system may include any tool or set of tools operable to calculate, estimate, determine, classify, process, transmit, receive, retrieve, originate, switch, store, display, communicate, indicate, detect, record, reproduce, dispose of, or utilize information, intelligence, or data of any form for commercial, scientific, control, or other purposes. For example, an information processing system may be a personal computer (e.g., a desktop or laptop computer), a tablet computer, a mobile device (e.g., a personal digital assistant (PDA) or smartphone), a server (e.g., a blade server or rack server), a network storage device, or any other suitable device, and its size, shape, performance, functionality, and price may vary. An information processing system may include random access memory (RAM), one or more processing resources (such as a central processing unit (CPU) or hardware or software control logic), ROM, and / or other types of non-volatile memory. Additional components of an information processing system may include one or more disk drives, one or more network ports for communicating with external devices, and various input and output (I / O) devices (such as a keyboard, mouse, touchscreen, and / or video display). The information processing system may also include one or more buses operable to transmit communication between various hardware components.

[0021] In one implementation scheme Figure 1 The IHS 100 includes a processor 102 connected to a bus 104. The bus 104 serves as a connection between the processor 102 and other components of the IHS 100. An input device 106 is coupled to the processor 102 to provide input to the processor 102. Examples of input devices may include a keyboard, a touchscreen, pointing devices (such as a mouse, trackball, and trackpad), and / or a variety of other input devices known in the art. Program and data are stored on a mass storage device 108 coupled to the processor 102. Examples of mass storage devices may include hard disks, optical disks, magneto-optical disks, solid-state storage devices, and / or a variety of other mass storage devices known in the art. The IHS 100 also includes a display 110 coupled to the processor 102 via a video controller 112. System memory 114 is coupled to the processor 102 to provide fast storage to the processor to facilitate the execution of computer programs by the processor 102. Examples of system memory may include random access memory (RAM) devices such as dynamic RAM (DRAM), synchronous DRAM (SDRAM), solid-state memory devices, and / or a variety of other memory devices known in the art. In this implementation, chassis 116 houses some or all of the components of IHS 100. It should be understood that additional buses and intermediate circuitry may be deployed between the aforementioned components and processor 102 to facilitate interconnection between the components and processor 102.

[0022] Now refer to Figure 2 This illustration shows an embodiment of a networked system 200 in which the distributed secure communication system of this disclosure can be utilized. In the illustrated embodiment, the networked system 200 includes a plurality of computing systems 202a, 202b, up to 202c. In the embodiment, computing systems 202a-202c may be derived from the above-mentioned references. Figure 1 The IHS 100 discussed may be provided and / or may include some or all of the components of the IHS 100, and in a specific example may be provided by a server device. However, although discussed as being provided by a server device, those skilled in the art to which this disclosure pertains will recognize that the computing systems configured to be provided in the networked system 200 may include any computing systems that can operate similarly to the computing systems 202a-202c discussed below. In the illustrated embodiments, each of the computing systems may be coupled to a network 204, which may be provided by a local area network (LAN), the Internet, combinations thereof, and / or any other network that will be apparent to those skilled in the art to which this disclosure pertains.

[0023] In the illustrated embodiment, management system 206 is also coupled to network 204. In this embodiment, management system 206 may be configured as described above. Figure 1 The IHS 100 discussed herein provides, and / or may include some or all of the components of the IHS 100, and in a specific example may be provided by one or more management server devices configured to perform management functions of computing systems 202a-202c (e.g., SCP managers of SCP subsystems included in computing systems 202a-202c discussed below). In the illustrated embodiment, one or more network attachment devices 208 are also coupled to network 204. In the embodiment, one or more network attachment devices 208 may be provided by a variety of different network attachment devices accessible to computing systems 202a-202c via network 204, and in a specific example may be provided by one or more high-speed non-volatile memory (NVMe) storage devices configured to provide network-attached storage systems for any or all of computing systems 202a-202c. However, although a particular networked system 200 has been shown and described, those skilled in the art to which this disclosure pertains will recognize that the distributed secure communication system of this disclosure can be utilized with a variety of components and component configurations, and / or can be provided in a variety of computing system / network configurations, while remaining within the scope of this disclosure.

[0024] Now refer to Figure 3A The above reference is provided for an embodiment of a computing system 300. Figure 2Any or all of the computing systems 202a-202c discussed. Therefore, computing system 300 can be derived from the above references. Figure 1 The IHS 100 discussed herein provides, and / or may include some or all of the components of the IHS 100, and in a specific example may be provided by a server device. However, although shown and discussed as being provided by a server device, those skilled in the art to which this disclosure pertains will recognize that the functionality of the computing system 300 discussed below may be provided by other computing systems configured to operate similarly to the computing system 300 discussed below. In the illustrated embodiment, the computing system 300 includes a chassis 302 housing the components of the computing system 300, only some of which are shown below.

[0025] For example, chassis 302 may house a system control processor (SCP) subsystem 304 provided in accordance with the teachings of this disclosure to perform the distributed secure communication functions discussed in more detail below. In some examples, SCP subsystem 304 may be conceptualized as an “enhanced” SmartNIC device configured to perform functions not available in conventional SmartNIC devices, such as, for example, the platform root of trust functionality described by the inventors of this disclosure in U.S. Patent Application No. 17 / 027,835, filed September 22, 2020, Attorney General’s File No. 16356.2212US01, and / or the distributed key management functionality described by the inventors of this disclosure in U.S. Patent Application No. 17 / 071,268, filed October 15, 2020, Attorney General’s File No. 16356.2208US01, the disclosures of which are incorporated herein by reference in their entirety. However, although shown and described as an enhanced SmartNIC device provided by the SCP subsystem, those skilled in the art to which this disclosure pertains will understand that the SCP subsystem 304 may be replaced by a variety of other subsystems configured to perform the functions discussed below, while also remaining within the scope of this disclosure.

[0026] In the implementation plan, SCP subsystem 304 may be derived from the above references. Figure 1The IHS 100 discussed herein provides and / or may include some or all of the components of the IHS 100. In a specific example, SCP subsystem 304 may be provided as an SCP card configured to connect to a slot on a motherboard in chassis 302. In other examples, SCP subsystem 304 may be integrated into the motherboard in chassis 302. In still other examples, SCP subsystem 304 may be a separate / common motherboard circuit board connected to the motherboard in chassis 302 (e.g., a two-part motherboard having a first part enabling conventional motherboard functions and a second part enabling SCP functions discussed below). However, while several specific examples are provided, those skilled in the art to which this disclosure pertains will understand that SCP subsystem 304 may be provided in computing system 300 in a variety of ways that fall within the scope of this disclosure.

[0027] Chassis 302 may also accommodate a central processing subsystem 306, which is coupled to the SCP subsystem 304 (e.g., via a compute high-speed link (CxL)) and may include the above references. Figure 1 The processor 102 discussed, the central processing unit (CPU) (such as an x86 main processor), the CPU memory (such as x86 main processor memory), and / or various other processing components that are obvious to those skilled in the art to which this disclosure pertains. The chassis 302 may also house a graphics processing subsystem 307, which is coupled to the SCP subsystem 304 and may include the above-mentioned references. Figure 1 The processor 102, graphics processing unit (GPU), GPU memory, and / or various other processing components discussed are obvious to those skilled in the art to which this disclosure pertains. As those skilled in the art will understand, in the example shown below, graphics processing subsystem 307 is connected to central processing subsystem 306 via SCP subsystem 304, such that SCP subsystem 304 acts as the “host” of graphics processing subsystem 307, although other central processing subsystem / graphics processing subsystem configurations will also fall within the scope of this disclosure.

[0028] Chassis 302 may also house a Basic Input / Output System (BIOS) subsystem 308, which is coupled to SCP subsystem 304 and central processing system 306. Those skilled in the art to which this disclosure pertains will recognize that the BIOS subsystem is provided by firmware configured to perform hardware initialization of computing system 300 during a boot process (e.g., power-on operation) or other initialization processes known in the art, and to perform runtime services for the operating system and / or other applications / programs provided by computing system 300. Furthermore, although described as a BIOS subsystem, those skilled in the art to which this disclosure pertains will recognize that BIOS subsystem 308 may be replaced by a Universal Extensible Firmware Interface (UEFI) subsystem, which defines the software interface between the operating system and firmware in computing system 300 and is provided to replace the BIOS subsystem (while supporting traditional BIOS services).

[0029] In the illustrated embodiment, chassis 302 may also accommodate boot storage device 308a, which is coupled to SCP subsystem 304 and BIOS subsystem 308, and those skilled in the art to which this disclosure pertains will recognize that the boot storage device may store a boot image accessible to and utilized by the BIOS subsystem 308 during boot operations. For example, boot storage device 308a may be manufactured using materials available from Pebble City, Texas, USA. The Boot Optimized Storage Solution (BOSS) of the corporation is provided, although other boot storage devices will also fall within the scope of this disclosure. In the illustrated embodiment, chassis 302 may also house a Baseboard Management Controller (BMC) subsystem 310, which is coupled to SCP subsystem 304 and central processing subsystem 306 (e.g., via a high-speed peripheral component interconnect (PCIe) link), and those skilled in the art to which this disclosure pertains will recognize that the BMC subsystem is configured to manage the interface between system management software in computing system 300 and hardware in computing system 300, and to perform other BMC operations that are obvious to those skilled in the art to which this disclosure pertains.

[0030] The chassis 302 may also accommodate one or more input / output (I / O) devices 312 coupled to (or provide coupling for) said I / O devices. Therefore, those skilled in the art to which this disclosure pertains will recognize that one or more I / O devices 312 may be accommodated within the chassis 302 and connected to internal connectors (e.g., on a motherboard within the chassis 302), or may be disposed externally to the chassis 302 and connected to external connectors (e.g., on an outer surface of the chassis 302). Figure 3AAs shown, one or more I / O devices 312 may include one or more high-speed peripheral component interconnect (PCIe) devices 312a (as one or more I / O devices 312 or other than one or more other I / O devices). For example, one or more PCIe devices 312a may include NVMe storage devices housed in chassis 302 (i.e., connected to an internal connector on a motherboard located in chassis 302) or outside chassis 302 (i.e., connected to an external connector on an external surface of chassis 302). However, while specific I / O devices and / or PCI devices have been described, those skilled in the art to which this disclosure pertains will recognize that a variety of other I / O devices will also fall within the scope of this disclosure. Chassis 302 may also house one or more field-programmable gate array (FPGA) devices 313, which are coupled to SCP subsystem 304 and can be programmed, as discussed below, to perform any of the various functions of computing system 300 and / or SCP subsystem 304.

[0031] The chassis 302 may also accommodate one or more first components 314 coupled to each of the BIOS subsystem 308 and the BMC subsystem 310, and one or more second components 316 coupled to at least one of the first components 314. In a specific example, one or more first components 314 and one or more second components 316 may include complex programmable logic devices (CPLDs), power systems, and / or a variety of other computing system components known in the art. However, while a particular computing system 300 has been shown, those skilled in the art to which this disclosure pertains will recognize that a computing system (or other means of operating in a manner similar to that described below for computing system 300, in accordance with the teachings of this disclosure) may include a variety of components and / or component configurations for providing general computing system functions and the functions discussed below, while remaining within the scope of this disclosure. For example, Figure 3B An implementation scheme of computing system 300 is shown, wherein the above references are omitted. Figure 3A The described BMC subsystem 310, and the SCP subsystem 304 are configured to provide the BMC subsystem 304a, which performs... Figure 3A The functions of the BMC subsystem 310 in the system.

[0032] Now refer to Figure 4 The above reference illustrates an implementation scheme of SCP subsystem 400. Figure 3A and Figure 3B The SCP subsystem 304 is discussed above. Therefore, SCP subsystem 400 can be referenced from the above. Figure 1The IHS 100 discussed herein is provided, and / or may include some or all of the components of the IHS 100, and in specific examples may be provided as an SCP card, integrated into a motherboard, or provided as a separate / common motherboard circuit board. Furthermore, although shown and discussed as being provided in different ways within computing system 400, those skilled in the art to which this disclosure pertains will recognize that the functionality of the SCP subsystem 400 discussed below may be provided by other means configured to operate similarly to the SCP subsystem 400 discussed below.

[0033] In the illustrated embodiment, the SCP subsystem 400 includes a chassis 402 (e.g., a circuit board) supporting the components of the SCP subsystem 400, only some of which are shown below. For example, the chassis 302 may support one or more SCP processors (not shown, but may include those referenced above). Figure 1 The processor 102 discussed herein is part of the SCP processing system and the SCP memory system (not shown, but may include those referenced above). Figure 1 The memory 114 discussed herein is coupled to an SCP processing system and includes instructions that, when executed by the SCP processing system, cause the SCP processing system to provide an SCP Distributed Secure Communication Engine 404, which is configured to perform the functions of the SCP Distributed Secure Communication Engine and / or SCP subsystems discussed below. In a specific example, the SCP processing system providing the SCP Distributed Secure Communication Engine 404 may be provided by an ARM processor core in an ARM-based processor, although other processing systems will also fall within the scope of this disclosure.

[0034] The chassis 302 may also support a storage system (not shown, but may include the above references). Figure 1 The storage device 108 discussed above, the SCP memory system discussed above, etc., said storage system is coupled to the SCP Distributed Secure Communication Engine 404 (e.g., through coupling between the storage system 406 and the SCP processing system), and may include an SCP Distributed Secure Communication Database 406 capable of storing private keys, public keys, and / or any other information utilized by the SCP Distributed Secure Communication Engine 404 as discussed below. Therefore, those skilled in the art to which this disclosure pertains will understand that the storage system providing the SCP Distributed Secure Communication Database 406 may include a variety of secure storage devices and / or security subsystems known in the art.

[0035] Chassis 402 may also support communication system 408, which is coupled to SCP distributed security communication engine 404 (e.g., via coupling between communication system 408 and SCP processing system), and in the illustrated embodiment, the communication system includes: configured to connect SCP subsystem 400 to the above reference. Figure 2 The network interface controller (NIC) subsystem 408a (e.g., Ethernet subsystem) of the network 204 under discussion is coupled to the SCP subsystem 400 and included in Figure 3A and Figure 3B The components of the computing system 300 and / or the components connected to the computing system are either part of the component connection subsystem 408b, and any other communication components (e.g., wireless communication systems) that are obvious to those skilled in the art to which this disclosure pertains. Near Field Communication (NFC) components, WiFi components, etc.

[0036] Therefore, the communication system 408 may include any of the connections between the SCP subsystem 400 and the network 204, the central processing subsystem 306, the graphics processing subsystem 307, the BIOS subsystem 308, the boot storage device 308a, the BMC subsystem 310, one or more I / O devices 312, one or more FPGA devices 313, and / or any other components utilized with the computing systems 202a / 300. For example, the component connectivity subsystem 408b may include: the CxLRoot.mem / .cache subsystem coupled to the central processing subsystem 306 and the out-of-band (OOB) management subsystem coupled to the BMC subsystem 310, and the CxL host subsystem coupled to components in the computing system 300. However, while a particular SCP subsystem 400 has been shown and described, those skilled in the art to which this disclosure pertains will recognize that an SCP subsystem (or other means of operating in a manner similar to that described below in accordance with the teachings of this disclosure) may include a variety of components (e.g., local memory, one or more embedded FPGA devices, a high-speed non-volatile memory (NVMe) emulation subsystem between the SCP cloning engine 404 and the CxLRoot.mem / .cache subsystem discussed above) and / or component configurations for providing the functionality discussed below, while also remaining within the scope of this disclosure.

[0037] Now refer to Figure 5A and Figure 5BThis document illustrates an embodiment of a method 500 for providing distributed secure communication. As discussed below, the systems and methods of this disclosure can provide an SCP subsystem in a computing system that, after performing authentication operations to authenticate other SCP subsystems and establishing secure communication channels with those other SCP subsystems, operates to prove authentication for each of those other SCP subsystems. This allows those other SCP subsystems to establish secure communication channels with each other without performing authentication operations. For example, the distributed secure communication system of this disclosure may include a first SCP subsystem coupled to a second SCP subsystem and a third SCP subsystem via a network. The first SCP subsystem identifies the second SCP subsystem, signs a first SCP authentication communication with a first private key to provide a first signed SCP authentication communication, and transmits the first signed SCP authentication communication to the second SCP subsystem. The first SCP subsystem then receives a second signed SCP authentication communication from the second SCP subsystem, authenticates the second signed SCP authentication communication using a second public key associated with the second SCP subsystem, and, in response, establishes a first secure communication channel with the second SCP subsystem. The first SCP subsystem then receives proof of authentication for the third SCP subsystem from the second SCP subsystem, and in response, establishes a second secure communication channel with the third SCP subsystem without transmitting signed SCP authentication communications. This reduces the execution of redundant authentication operations typically used to establish secure communication channels, thus allowing for faster establishment of secure communication networks compared to conventional secure communication systems.

[0038] Method 500 begins at block 502, where the second SCP subsystem identifies the first SCP subsystem. In the specific example provided below, the second SCP subsystem, provided by SCP subsystem 304 in computing system 202b / 300, performs an authentication operation with the first SCP subsystem, provided by SCP subsystem 304 in computing system 202a / 300, to authenticate the first SCP subsystem and establish a first secure communication channel with it; performs an authentication operation with a third SCP subsystem, provided by SCP subsystem 304 in computing system 202c / 300, to authenticate the third SCP subsystem and establish a second secure communication channel with it; and then verifies the authentication of the third SCP subsystem to the first SCP subsystem and the authentication of the first SCP subsystem to the third SCP subsystem, which allows the first and third SCP subsystems to establish a third secure communication channel with each other without performing an authentication operation. However, those skilled in the art to which this disclosure pertains will understand that any SCP subsystem can authenticate any other SCP subsystem or cause authentication of other SCP subsystems to prove itself to them, and then subsequently prove authentication of those other SCP subsystems, while remaining within the scope of this disclosure. Furthermore, while SCP subsystems in computing systems 202a / 202c are shown and described, those skilled in the art to which this disclosure pertains will understand that SCP subsystems can be “standalone” or otherwise provided outside of any computing system (e.g., outside of a server device), while also remaining within the scope of this disclosure.

[0039] In an implementation, at or before block 502, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of the computing system 202b / 300 may be powered on, reset, rebooted, and / or otherwise initialized (e.g., in response to the initialization of the computing system 202b / 300), and in response, may be operable to verify, confirm, and / or otherwise authenticate the SCP boot image or other code it uses for initialization operations. For example, authentication of the SCP boot image by the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of the computing system 202b / 300 may include: generating a hash value from the SCP boot image and checking the hash value against a verified hash value; verifying that the SCP boot image is signed with a corresponding private key using a verified public key; performing other measurements on the SCP boot image to verify its authenticity; and / or performing any other authentication operations, which those skilled in the art to which this disclosure pertains to will recognize as authenticating the code or other software that will be used to operate the SCP subsystem 304 in the computing system 202b / 300. Furthermore, while the SCP subsystem 304 in computing systems 202b / 300 is discussed as authenticating the code or other software it will be used to operate, those skilled in the art to which this disclosure pertains will understand that the SCP subsystem 304 in computing systems 202a / 300, up to 202c / 300, can perform similar authentication operations while remaining within the scope of this disclosure.

[0040] In some embodiments, any of computing systems 202a / 300, 202b / 300, up to 202c / 300 may be configured to perform the platform trust root functionality described in U.S. Patent Application No. 17 / 027,835, Agent's File No. 16356.2212US01, filed September 22, 2020, the disclosure of which is incorporated herein by reference in its entirety. Thus, after authenticating the code or other software it will use to operate, any of the SCP subsystems 304 in computing systems 202a / 300, 202b / 300, up to 202c / 300 may authenticate components and / or devices in their respective computing systems, and allow those components and / or devices to authenticate their respective configurations to compute other components and / or devices in the computing system. Furthermore, any of the SCP subsystems 304 in computing systems 202a / 300, 202b / 300, up to 202c / 300, can be configured to periodically re-authenticate components and / or devices in their respective computing systems, and to allow those components and / or devices to re-authenticate other components and / or other devices in their respective computing systems, as discussed in more detail below.

[0041] As those skilled in the art to which this disclosure pertains will understand, even if the SCP distributed secure communication engine 404 in the SCP subsystem 304 of any of the computing systems 202a / 300, 202b / 300, and / or 202c / 300 fails to authenticate its SCP boot code image, the SCP subsystem 304 may still use the SCP boot code image to complete its initialization operations, but will enter an "unauthenticated" / "unverified" / "untrusted" state for possible repair. Therefore, while the following discussion assumes that each of the SCP subsystems 304 in the computing systems 202a / 300, 202b / 300, and / or 202c / 300 operates using an authenticated code, those skilled in the art to which this disclosure pertains will understand that, in the event that the SCP boot image cannot be authenticated by the SCP subsystem, a repair operation (e.g., a remote repair operation performed by the management system 206) may be performed to repair the "unauthenticated" / "unverified" / "untrusted" state of the SCP subsystem in order to allow the establishment of a secure communication channel with the SCP subsystem. However, if the "Uncertified" / "Unverified" / "Untrusted" state of the SCP subsystem cannot be restored, it may be impossible to establish a secure communication channel with the SCP subsystem as discussed below.

[0042] refer to Figure 6AIn the embodiment of block 502, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can perform SCP subsystem communication operation 600, which may include identifying the SCP subsystem 304 in computing system 202a / 300. For example, SCP subsystem communication operation 600 may include: the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 generating SCP subsystem discovery communication and broadcasting the SCP subsystem discovery communication via the NIC subsystem 408a in its communication system 408 and via network 204. Then, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202a / 300 can receive those SCP subsystem discovery communications via network 204 and the NIC subsystem 408a in its communication system 408, and respond by transmitting SCP subsystem identification communication via the NIC subsystem 408a in its communication system 408 and via network 204. Then, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can receive the SCP subsystem identification communication via network 204 and the NIC subsystem 408a in its communication system 408, and identify the SCP subsystem 304 in computing system 202b / 300 at block 502. As those skilled in the art to which this disclosure pertains will understand, multiple SCP subsystems (e.g., in different computing systems) can respond to the SCP subsystem discovery communication broadcast by the SCP subsystem 304 in computing system 202b / 300, and therefore the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can identify one or more of those SCP subsystems at block 502 by, for example, selecting / identifying one or more of the SCP subsystems that responded to the SCP subsystem discovery communication.

[0043] However, while specific techniques for identifying SCP subsystems are shown and described herein, those skilled in the art to which this disclosure pertains will recognize that identifying SCP subsystems at box 502 can be performed using a variety of techniques that will also fall within the scope of this disclosure. For example, any number of “similar” SCP subsystems can be identified via a connection infrastructure including buses, network connections, and / or other coupled connections (e.g., Figure 2The networked system 200 in the system connects the two subsystems, and any two “similar” SCP subsystems can exchange unique similar identifiers (e.g., identifier exchange between SCP subsystems in computing systems 202a / 300 and 202b / 300), which can be secured based on certificates, for example, from a Certificate Authority (CA) provided by the manufacturer of those SCP subsystems (or the manufacturer of the computing system in which those SCP subsystems are provided). Therefore, at box 502, the SCP subsystem can monitor specific channels on the connectivity infrastructure to listen for the SCP subsystem discovery and / or identification communications discussed above, wherein, in some embodiments, the channels described are reserved for SCP subsystem connection queries against similar SCP subsystems. In some specific examples, similar SCP identifier exchange may include identifying similar equivalent devices used to establish secure communication channels described below.

[0044] Method 500 then proceeds to box 504, where the second SCP subsystem signs the second SCP authentication communication with a second private key and transmits the second signed SCP authentication communication to the first SCP subsystem. In the implementation, at box 504, and as Figure 6A As part of the SCP subsystem communication operation 600 shown, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can use a “second” private key controlled by the SCP subsystem 304 of computing system 202b / 300 to sign a “second” SCP authentication communication to provide a “second” signed SCP authentication communication, and transmit the second signed SCP authentication communication to the SCP subsystem 304 in computing system 202b / 300 via the NIC subsystem 408a in its communication system 408 and via network 204. For example, the second private key used by the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 to provide the second signed SCP authentication communication at box 504 can be retrieved from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations as discussed in more detail below, and is securely stored in its SCP distributed secure communication database 406. Furthermore, the second private key may be associated with a corresponding second public key, which may be accessible through the management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations as discussed in more detail below.

[0045] As those skilled in the art to which this disclosure pertains will understand, block 504 may be associated with one or more creation actions, in which a unique key pair derived from a certificate provided by a Certificate Authority (CA) is created, and said unique key pair may be unique with respect to each SCP subsystem and / or any specific point in the SCP subsystem initialization, making it impossible for an attacker to create said unique key pair to gain access to the system using keys that may have been collected, for example, in previous bootstrapping, rebooting, or other initialization cycles. Furthermore, during any key exchange operation between SCP subsystem pairs, an initial secure communication channel may be created, and key information may be received by each SCP subsystem in the pair and stored in a key vault protected storage area, and as discussed below and for each subsequent SCP subsystem added to the structure, the various SCP subsystems may exchange public key pairs through the initial secure channel to allow all SCP subsystems in the structure to use a public key mechanism and simplify the overall secure communication channel of the structure. Similarly, when each SCP subsystem is added to the structure, key information from previous SCP subsystems may be distributed to other members of the structure to allow the establishment of a distributed secure communication channel for the structure. Furthermore, to protect private key information in any exchange, only public keys may be exchanged.

[0046] Therefore, at box 504, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202a / 300 can receive (transmitted by the SCP subsystem 304 in computing system 202b / 300) a second signed SCP authentication communication via the NIC subsystem 408a in its communication system 408. As discussed in more detail below with reference to the SCP subsystem 304 of computing system 202b / 300, in response to receiving the second signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202b / 300, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202a / 300 is operable to perform an authentication operation using a second public key associated with the SCP subsystem 304 in computing system 202b / 300 (e.g., a second public key retrieved by the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202a / 300) to authenticate the second signed SCP authentication communication. As also described below, authentication of the second signed SCP-authenticated communication by SCP subsystem 304 in computing system 202a / 300 may allow the establishment of a first secure communication channel as discussed below.

[0047] Method 500 then proceeds to box 506, where the second SCP subsystem receives the first signed SCP authentication communication from the first SCP subsystem and authenticates it using the first public key. In the implementation, at box 506, and as Figure 6AAs part of the SCP subsystem communication operation 600 shown, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202a / 300 can use a “first” private key controlled by the SCP subsystem 304 of computing system 202a / 300 to sign a “first” SCP authentication communication to provide a “first” signed SCP authentication communication, and transmit the first signed SCP authentication communication to the SCP subsystem 304 in computing system 202b / 300 via the NIC subsystem 408a in its communication system 408 and via network 204. For example, the first private key used by the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202a / 300 to provide the first signed SCP authentication communication at box 504 can be retrieved from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations, and is securely stored in its SCP distributed secure communication database 406. Furthermore, the first private key may be associated with a corresponding first public key, which can be accessed through the management system 206, one or more network attachment devices 208 (e.g., the network-attached storage system in this example), and / or other locations. Therefore, in some embodiments, the public / private key pair utilized by the SCP subsystem during method 500 can be securely stored and accessed via network 204.

[0048] Therefore, at block 506, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 can receive (transmitted by the SCP subsystem 304 in computing system 202a / 300) the first signed SCP authentication communication via the NIC subsystem 408a in its communication system 408. In response to receiving the first signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202a / 300, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 is operable to perform various public / private key authentication operations that use a first public key associated with the SCP subsystem 304 in computing system 202a / 300 to authenticate the first signed SCP authentication communication.

[0049] In some implementations, during or before block 506, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can retrieve a first public key from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations via network 204, and use the first public key pair at block 506 to authenticate the first signed SCP authentication communication. Therefore, the first public key used to authenticate the first signed SCP authentication communication can be retrieved in response to receiving the first signed SCP authentication communication. However, those skilled in the art to which this disclosure pertains will recognize that the first public key may have previously been stored in the SCP secure communication database 406 in the SCP subsystem 400 of computing system 202b / 300, and can be retrieved from said secure storage device in response to receiving the first signed SCP authentication communication, while also remaining within the scope of this disclosure.

[0050] Method 500 then proceeds to box 508, where the second SCP subsystem establishes a first secure communication channel with the first SCP subsystem. (See reference) Figure 6B In the implementation of block 508, and in response to authenticating a first signed SCP authentication communication received from SCP subsystem 304 in computing system 202a / 300 (and together with authenticating a second signed SCP authentication communication received from SCP subsystem 304 in computing system 202b / 300), the SCP distributed secure communication engine 404 in SCP subsystem 304 of computing system 202b / 300 may establish a secure communication channel 602 with SCP subsystem 304 in computing system 202a / 300. As those skilled in the art to which this disclosure pertains will understand, the authentication of the first signed SCP-authenticated communication received from SCP subsystem 304 in computing system 202a / 300 can be considered a “trust verification” operation performed by SCP subsystem 304 in computing system 202b / 300. This, together with the authentication of the second signed SCP-authenticated communication by SCP subsystem 304 in computing system 202a / 300 discussed above, allows SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202a / 300 to trust each other, enabling them to exchange secure communications.

[0051] In the implementation, SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202a / 300 can subsequently communicate via secure communication channel 602 using keys exchanged using a distributed key management function, which is described by the inventors of this disclosure in U.S. Patent Application No. 17 / 071,268, Agent's File No. 16356.2208US01, filed October 15, 2020, the disclosure of which is incorporated herein by reference in its entirety. In a specific example, the use of secure communication channel 602 can be performed using public key infrastructure (PKI) key technology and can provide secure encrypted communication exchange between SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202a / 300. As those skilled in the art to which this disclosure pertains will understand, after establishing a secure communication channel 602, the SCP subsystems 304 in computing systems 202b / 300 and 202a / 300 can securely exchange various types of data via the secure communication channel 602. For example, in some embodiments, the SCP subsystems 304 in computing systems 202b / 300 and 202a / 300 can exchange control and / or management communications via the secure communication channel 602, while simultaneously exchanging other data communications (e.g., non-control / non-management data) via some other, relatively insecure communication channel provided between the SCP subsystems 304 in computing systems 202b / 300 and 202a / 300. Therefore, an SCP control plane structure separate from the SCP data plane structure can be provided, and in some examples, data and management control operations can also be separated within said SCP control plane structure. However, in other embodiments, the SCP subsystem 304 in computing system 202b / 300 and the SCP subsystem 304 in computing system 202a / 300 may exchange all data communications via secure communication channel 602, while also remaining within the scope of this disclosure.

[0052] Method 500 then proceeds to box 510, where the second SCP subsystem identifies the third SCP subsystem. (See reference) Figure 6CIn the embodiment of block 510, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can perform an SCP subsystem communication operation 604, which operates to identify the SCP subsystem 304 in computing system 202c / 300. Similar to the discussion above, the SCP subsystem communication operation 604 may include: the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 generating an SCP subsystem discovery communication and broadcasting the SCP subsystem discovery communication via the NIC subsystem 408a in its communication system 408 and via network 204. The SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202c / 300 can then receive those SCP subsystem discovery communications via network 204 and the NIC subsystem 408a in its communication system 408, and respond by transmitting SCP subsystem identification communications via the NIC subsystem 408a in its communication system 408 and via network 204. Then, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 can receive the SCP subsystem identification communication via network 204 and the NIC subsystem 408a in its communication system 408, and identify the SCP subsystem 304 in computing system 202c / 300 at box 502. As discussed above, multiple SCP subsystems (e.g., in different computing systems) can respond to the SCP subsystem discovery communication broadcast by the SCP subsystem 304 in computing system 202b / 300, and therefore, at the same time as the identification of the SCP subsystem 304 in computing system 202a / 300 at box 502 or at a different time, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 can identify the SCP subsystem 304 in computing system 202c / 300 at box 510.

[0053] Method 500 then proceeds to box 512, where the second SCP subsystem signs the second SCP authentication communication with the second private key and transmits the second signed SCP authentication communication to the third SCP subsystem. In the implementation, at box 512, and as Figure 6CAs part of the SCP subsystem communication operation 604 shown, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 can use a “second” private key controlled by the SCP subsystem 304 of computing system 202b / 300 to sign a “second” SCP authentication communication to provide a “second” signed SCP authentication communication, and transmit the second signed SCP authentication communication to the SCP subsystem 304 in computing system 202c / 300 via the NIC subsystem 408a in its communication system 408 and via network 204. As discussed above, the second private key used by the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 to provide the second signed SCP authentication communication at box 512 can be retrieved from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations, and can be securely stored in its SCP Distributed Secure Communication Database 406. Furthermore, the second private key may be associated with a corresponding second public key, which may be accessible through the management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations as discussed in more detail below.

[0054] Therefore, at box 512, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202c / 300 can receive the second signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202b / 300 via the NIC subsystem 408a in its communication system 408. As discussed in more detail below with reference to the SCP subsystem 304 of computing system 202b / 300, in response to receiving the second signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202b / 300, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202c / 300 is operable to perform an authentication operation, which (e.g., using a second public key associated with the SCP subsystem 304 in computing system 202b / 300 and possibly retrieved by the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202c / 300) authenticates the second signed SCP authentication communication. As also described below, authentication of the second signed SCP-authenticated communication by SCP subsystem 304 in computing system 202c / 300 may allow the establishment of a second secure communication channel as discussed below.

[0055] Method 500 then proceeds to box 514, where the second SCP subsystem receives third signed SCP-authenticated communication from the third SCP subsystem and authenticates it using the third public key. In the implementation, at box 514, and as Figure 6C As part of the SCP subsystem communication operation 604 shown, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202c / 300 can use a “third” private key controlled by the SCP subsystem 304 of computing system 202c / 300 to sign a “third” SCP authentication communication to provide a “third” signed SCP authentication communication, and transmit the third signed SCP authentication communication to the SCP subsystem 304 in computing system 202b / 300 via the NIC subsystem 408a in its communication system 408 and via network 204. For example, the third private key used by the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202c / 300 to provide the third signed SCP authentication communication at box 514 can be retrieved from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations, and is securely stored in its SCP distributed secure communication database 406. Furthermore, a third private key may be associated with a corresponding third public key, which can be accessed through management system 206, one or more network attachment devices 208 (e.g., a network-attached storage system in this example), and / or other locations. Therefore, in some embodiments, the public / private key pair utilized by the SCP subsystem during method 500 can be securely stored and accessed via network 204.

[0056] Therefore, at box 514, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 can receive a third signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202c / 300 via the NIC subsystem 408a in its communication system 408. In response to receiving the third signed SCP authentication communication transmitted by the SCP subsystem 304 in computing system 202c / 300, the SCP Distributed Secure Communication Engine 404 in the SCP subsystem 304 of computing system 202b / 300 is operable to perform various public / private key authentication operations, which use a third public key associated with the SCP subsystem 304 in computing system 202c / 300 to authenticate the third signed SCP authentication communication.

[0057] In some implementations, during or before block 514, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can retrieve a third public key from management system 206, one or more network attachment devices 208 (e.g., the network attachment storage system in this example), and / or other locations via network 204, and use the third public key to authenticate the third signed SCP authentication communication. Therefore, the third public key used to authenticate the third signed SCP authentication communication can be retrieved in response to receiving the third signed SCP authentication communication. However, those skilled in the art to which this disclosure pertains will recognize that the third public key may have previously been stored in the SCP secure communication database 406 in the SCP subsystem 400 of computing system 202b / 300, and can be retrieved from the secure storage device in response to receiving the third signed SCP authentication communication, while also remaining within the scope of this disclosure.

[0058] Method 500 then proceeds to box 516, where the second SCP subsystem establishes a second secure communication channel with the third SCP subsystem. (See reference) Figure 6D In the implementation of block 516, and in response to authenticating a third signed SCP authentication communication received from SCP subsystem 304 in computing system 202c / 300 (and together with authenticating a second signed SCP authentication communication received from SCP subsystem 304 in computing system 202b / 300), the SCP distributed secure communication engine 404 in SCP subsystem 304 of computing system 202b / 300 may establish a secure communication channel 605 with SCP subsystem 304 in computing system 202c / 300. As those skilled in the art to which this disclosure pertains will understand, the authentication of a third signed SCP-authenticated communication received from SCP subsystem 304 in computing system 202c / 300 can be considered a “trust verification” operation performed by SCP subsystem 304 in computing system 202b / 300. This, together with the authentication of the second signed SCP-authenticated communication by SCP subsystem 304 in computing system 202c / 300 as discussed above, allows SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202c / 300 to trust each other, enabling them to exchange secure communications.

[0059] Similar to those described above, SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202c / 300 can subsequently communicate via secure communication channel 605 using keys exchanged using a distributed key management function, which is described by the inventors of this disclosure in U.S. Patent Application No. 17 / 071,268, Agent's File No. 16356.2208US01, filed October 15, 2020, the disclosure of which is incorporated herein by reference in its entirety. Therefore, the use of secure communication channel 605 can be performed using Public Key Infrastructure (PKI) key technology and can provide secure encrypted communication exchange between SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202c / 300. As those skilled in the art to which this disclosure pertains will understand, after establishing a secure communication channel 605, the SCP subsystems 304 in computing systems 202b / 300 and 202c / 300 can securely exchange various types of data via the secure communication channel 605. For example, in some embodiments, the SCP subsystems 304 in computing systems 202b / 300 and 202c / 300 can exchange control and / or management communications via the secure communication channel 605, while simultaneously exchanging other data communications (e.g., non-control / non-management data) via a separate, relatively insecure communication channel provided between the SCP subsystems 304 in computing systems 202b / 300 and 202c / 300. Therefore, an SCP control plane structure separate from the SCP data plane structure can be provided, and in some examples, data and management control operations can also be separated within said SCP control plane structure. However, in other embodiments, SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202c / 300 may exchange all data communications via secure communication channel 605, while remaining within the scope of this disclosure.

[0060] Method 500 then proceeds to box 518, where the second SCP subsystem certifies its authentication of the third SCP subsystem to the first SCP subsystem. (See reference) Figure 6EIn the embodiment of block 518, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can perform an SCP proof operation 606, which may include generating SCP proof communication and transmitting the SCP proof communication to computing system 202a / 300 via the NIC subsystem 408a in its communication system 408 and via network 204 using a secure communication channel 602. In a specific example, the SCP proof communication transmitted by the SCP subsystem 304 in computing system 202b / 300 at block 518 may include a third public key associated with the SCP subsystem 304 in computing system 202c / 300, SCP subsystem communication connection information identifying the communication connection to the SCP subsystem 304 in computing system 202c / 300, and / or any other information that a person skilled in the art to which this disclosure pertains will recognize, which provides the functionality discussed below. However, while specific SCP authentication communications are described, those skilled in the art to which this disclosure pertains will understand that a variety of information can be used to identify SCP subsystem 304 in computing system 202c / 300 and to authenticate it, while also remaining within the scope of this disclosure.

[0061] In some implementations, a common structure key pair can be created at any time after communication between similar SCP subsystems is established to simplify the number of keys required between endpoints (e.g., SCP subsystems). As those skilled in the art to which this disclosure pertains will understand, the use of a common structure key pair simplifies the transfer of secure information between SCP systems in the structure by allowing a single key to protect transmitted data and allowing information to be delivered to multiple SCP subsystems in the structure using common communication methods (e.g., multicast channels in the IP domain). As the number of SCP subsystems expands, such operation optimizes the efficiency of information transfer over a single channel (e.g., relative to a direct link used to each SCP in the structure). In some implementations, the public key pair can be created after the first two SCP subsystems have established a secure communication channel. For example, the public key can be created by one of the SCP subsystems in the pair, and then the public key can be encrypted and delivered to the other SCP subsystem in the pair in the “initial” structure. The public key can then be used to verify communication between the two SCP subsystems, and when a third SCP subsystem joins the structure using a secure communication link established through direct peering, the public key pair can be encrypted and delivered to the subsystem in the third SCP structure to allow the public key to be used for secure communication. As those skilled in the art to which this disclosure pertains will understand, this operation can then be repeated for each subsequent SCP subsystem to which the structure is added.

[0062] Therefore, at box 518, as part of SCP authentication operation 606, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202a / 300 can receive SCP authentication communications transmitted via secure communication channel 602 through network 204 and its communication system 408's NIC subsystem 408a. As those skilled in the art to which this disclosure pertains will understand, receiving SCP authentication communications via secure communication channel 602 allows those SCP authentication communications to be trusted (i.e., based on the authentication / trust verification operations performed above to establish secure communication channel 602), and thus the identification of the SCP subsystem 304 in computing system 202c / 300 in the SCP authentication communications is itself operable to authenticate the SCP subsystem 304 in computing system 202c / 300. However, those skilled in the art to which this disclosure pertains will understand that additional information can be provided to the SCP subsystem 304 in computing system 202a / 300 to authenticate the SCP subsystem 304 in computing system 202c / 300, while also remaining within the scope of this disclosure.

[0063] Method 500 then proceeds to box 520, where the second SCP subsystem verifies its authentication of the first SCP subsystem to the third SCP subsystem. (See reference) Figure 6F In the embodiment of block 520, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202b / 300 can perform an SCP proof operation 608, which may include generating SCP proof communication and transmitting the SCP proof communication to computing system 202c / 300 via the NIC subsystem 408a in its communication system 408 and via network 204 using a secure communication channel 605. In a specific example, the SCP proof communication transmitted at block 520 by the SCP subsystem 304 in computing system 202b / 300 may include a first public key associated with the SCP subsystem 304 in computing system 202a / 300, SCP subsystem communication connection information identifying the communication connection to the SCP subsystem 304 in computing system 202a / 300, and / or any other information that a person skilled in the art to which this disclosure pertains will recognize, which provides the functionality discussed below. However, while specific SCP authentication communications are described, those skilled in the art to which this disclosure pertains will understand that a variety of information can be used to identify SCP subsystem 304 in computing system 202a / 300 and to authenticate it, while also remaining within the scope of this disclosure.

[0064] Therefore, at box 520, as part of SCP authentication operation 608, the SCP distributed secure communication engine 404 in the SCP subsystem 304 of computing system 202c / 300 can receive SCP authentication communications transmitted via secure communication channel 605 through network 204 and its communication system 408's NIC subsystem 408a. As those skilled in the art to which this disclosure pertains will understand, receiving SCP authentication communications via secure communication channel 605 allows those SCP authentication communications to be trusted (i.e., based on the authentication / trust verification operations performed above to establish secure communication channel 605), and thus the identification of the SCP subsystem 304 in computing system 202a / 300 in the SCP authentication communications is itself operable to authenticate the SCP subsystem 304 in computing system 202a / 300. However, those skilled in the art to which this disclosure pertains will understand that additional information can be provided to the SCP subsystem 304 in computing system 202c / 300 to authenticate the SCP subsystem 304 in computing system 202a / 300, while also remaining within the scope of this disclosure.

[0065] Method 500 then proceeds to box 522, where the first and third SCP subsystems establish a third secure communication channel without transmitting signed SCP-authenticated communications. (See reference) Figure 6G In the implementation of block 522, in response to authenticating the SCP subsystem 304 in computing system 202c / 300 to SCP subsystem 304 in computing system 202a / 300 and SCP subsystem 304 in computing system 202c / 300 to SCP subsystem 304 in computing system 202a / 300, the SCP distributed secure communication engine 404 in SCP subsystem 304 in each of computing systems 202a / 300 and 202c / 300 can establish a secure communication channel 610 between each other. As those skilled in the art to which this disclosure pertains will understand, the mutual attestation of each of the SCP subsystems 304 in computing systems 202c / 300 and 202a / 300 operates as a “trust verification”, which allows the SCP subsystems 304 in computing systems 202a / 300 and 202b / 300 to trust each other, enabling the exchange of secure communications between those SCP subsystems without the need to perform authentication operations (e.g., those performed during boxes 506 and 514 discussed above).

[0066] Similar to those discussed above, SCP subsystem 304 in computing system 202a / 300 and SCP subsystem 304 in computing system 202c / 300 can subsequently communicate via secure communication channel 610 using keys exchanged using a distributed key management function, the distributed key management function of which is described by the inventors of this disclosure in U.S. Patent Application No. 17 / 071,268, Agent's File No. 16356.2208US01, filed October 15, 2020, the disclosure of which is incorporated herein by reference in its entirety. Therefore, secure communication channel 610 can provide secure encrypted communication exchange between SCP subsystem 304 in computing system 202a / 300 and SCP subsystem 304 in computing system 202c / 300. As those skilled in the art to which this disclosure pertains will understand, after establishing a secure communication channel 610, the SCP subsystems 304 in computing systems 202a / 300 and 202c / 300 can securely exchange various types of data via the secure communication channel 610. For example, in some embodiments, the SCP subsystems 304 in computing systems 202a / 300 and 202c / 300 can exchange control and / or management communications via the secure communication channel 610, while simultaneously exchanging other data communications (e.g., non-control / non-management data) via some other, relatively insecure communication channel provided between the SCP subsystems 304 in computing systems 202a / 300 and 202c / 300. Therefore, an SCP control plane structure separate from the SCP data plane structure can be provided, and in some examples, data and management control operations can also be separated within said SCP control plane structure. However, in other embodiments, SCP subsystem 304 in computing system 202a / 300 and SCP subsystem 304 in computing system 202c / 300 may exchange all data communications via secure communication channel 610, while also remaining within the scope of this disclosure.

[0067] Method 500 then proceeds to block 524, wherein the first SCP subsystem, the second SCP subsystem, and the third SCP subsystem transmit communication via a first secure communication channel, a second secure communication channel, and a third secure communication channel. In an embodiment, at block 524 and as discussed above, SCP subsystem 304 in computing system 202a / 300 and SCP subsystem 304 in computing system 202b / 300 can securely exchange various data via secure communication channel 602, SCP subsystem 304 in computing system 202b / 300 and SCP subsystem 304 in computing system 202c / 300 can securely exchange various data via secure communication channel 605, and SCP subsystem 304 in computing system 202c / 300 and SCP subsystem 304 in computing system 202a / 300 can securely exchange various data via secure communication channel 610.

[0068] As those skilled in the art to which this disclosure pertains will understand, any SCP subsystem subsequently added to networked subsystem 200 can be authenticated by one of the SCP subsystems 304 in computing systems 202a / 300, 202b / 300, or 202c / 300 to establish a secure communication channel, and then authenticated to it with other SCP subsystems, enabling the establishment of secure communication channels with any of those SCP subsystems as well. Thus, additional SCP subsystems can be quickly and easily added to the secure communication “structure” to develop the secure communication structure. Therefore, the SCP subsystems 304 in computing systems 202a-202c / 300 can coordinate with each other by creating a secure SCP infrastructure business plane, which (effectively) creates a virtual exchange structure, establishes infrastructure control plane data exchange (e.g., operation and telemetry) between similar SCP subsystems, and eliminates duplicate SCP operations on similar SCP subsystems.

[0069] In some implementations, the SCP subsystem providing the secure communication structure is operable to perform the platform root of trust functionality described by the inventors of this disclosure in U.S. Patent Application No. 17 / 027,835, Petition No. 16356.2212US01, filed September 22, 2020, the disclosure of which is incorporated herein by reference in its entirety. Thus, the SCP subsystem is operable to periodically check whether any SCP subsystem (or its computing system) has been altered, and if so, remove the SCP subsystem from the secure communication structure (e.g., by closing the secure communication channel established with the SCP subsystem). Furthermore, any SCP subsystem removed from the secure communication structure may be prevented from accessing the public / private key pairs used to establish the secure communication channel as described above, but may be allowed to access those public / private key pairs again once they can be re-verified or otherwise authenticated.

[0070] Therefore, systems and methods have been described that can provide SCP subsystems in a server device, wherein after performing authentication operations to authenticate other SCP subsystems and establish secure communication channels with those other SCP subsystems, the SCP subsystem operates to prove authentication for each of those other SCP subsystems, allowing those other SCP subsystems to establish secure communication channels with each other without performing authentication operations. For example, the distributed secure communication system of this disclosure may include a first SCP subsystem coupled to a second SCP subsystem and a third SCP subsystem via a network. The first SCP subsystem identifies the second SCP subsystem, signs the first SCP authentication communication with a first private key to provide a first signed SCP authentication communication, and transmits the first signed SCP authentication communication to the second SCP subsystem. The first SCP subsystem then receives a second signed SCP authentication communication from the second SCP subsystem, authenticates the second signed SCP authentication communication using a second public key associated with the second SCP subsystem, and, in response, establishes a first secure communication channel with the second SCP subsystem. The first SCP subsystem then receives proof of authentication for the third SCP subsystem from the second SCP subsystem, and in response, establishes a second secure communication channel with the third SCP subsystem without transmitting signed SCP authentication communications. This reduces the execution of redundant authentication operations typically used to establish secure communication channels, thus allowing for faster establishment of secure communication networks compared to conventional secure communication systems.

[0071] While exemplary embodiments have been shown and described, a wide range of modifications, alterations, and substitutions are contemplated in the foregoing disclosure, and in some cases, some features of the embodiments may be employed without correspondingly using others. Therefore, it is appropriate to interpret the appended claims broadly and in a manner consistent with the scope of the embodiments disclosed herein.

Claims

1. A distributed secure communication system, comprising: The third system control processor (SCP) subsystem; The second SCP subsystem is network-coupled to the third SCP subsystem. as well as A first SCP subsystem, coupled to the second and third SCP subsystems via the network, wherein the first SCP subsystem is configured to: Identify the second SCP subsystem, and in response, perform a signed secure communication channel establishment procedure with the second SCP subsystem, including: The first SCP authentication communication is signed with the first private key to provide the first signed SCP authentication communication; Transmit the first signed SCP authentication communication to the second SCP subsystem; Receive a second signed SCP authentication communication from the second SCP subsystem, and in response, authenticate the second signed SCP authentication communication using a second public key associated with the second SCP subsystem; In response to authenticating the second signed SCP authentication communication, a first secure communication channel is established with the second SCP subsystem; and The authentication certificate for the third SCP subsystem is received from the second SCP subsystem via the first secure communication channel. The third SCP subsystem has established a second secure communication channel between the second SCP subsystem and the third SCP subsystem. In response, a third secure communication channel is established with the third SCP subsystem without performing the signed secure communication channel establishment process with the third SCP subsystem.

2. The system of claim 1, wherein the first SCP subsystem is configured to: Monitor the SCP subsystem and, in response, identify the second SCP subsystem.

3. The system of claim 1, wherein the first SCP subsystem is configured to: The second public key associated with the second SCP subsystem is retrieved via the network.

4. The system of claim 1, wherein the first SCP subsystem is configured to: First control communication with the second SCP subsystem is transmitted via the first secure communication channel; and The second control communication with the third SCP subsystem is transmitted through the third secure communication channel.

5. The system of claim 4, wherein the first SCP subsystem is configured to: First data communication with the second SCP subsystem is transmitted via a first insecure communication channel; and Second data communication with the third SCP subsystem is transmitted via a second insecure communication channel.

6. The system of claim 1, wherein the proof of the authentication of the third SCP subsystem comprises: A third public key, which is associated with the third SCP subsystem; as well as Third SCP subsystem communication connection information.

7. An information processing system (IHS) comprising: Processing system; as well as A memory system coupled to the processing system and including instructions that, when executed by the processing system, cause the processing system to provide a distributed secure communication engine, the distributed secure communication engine being configured to: Identify the second system control processor (SCP) subsystem, and in response, execute a signed secure communication channel establishment procedure with the second SCP subsystem, including: The first SCP authentication communication is signed with the first private key to provide the first signed SCP authentication communication; Transmit the first signed SCP authentication communication to the second SCP subsystem; Receive a second signed SCP authentication communication from the second SCP subsystem, and in response, authenticate the second signed SCP authentication communication using a second public key associated with the second SCP subsystem; In response to authenticating the second signed SCP authentication communication, a first secure communication channel is established with the second SCP subsystem; and The authentication certificate for the third SCP subsystem is received from the second SCP subsystem via the first secure communication channel. The third SCP subsystem has established a second secure communication channel between the second SCP subsystem and the third SCP subsystem. In response, a third secure communication channel is established with the third SCP subsystem without performing the signed secure communication channel establishment process with the third SCP subsystem.

8. The IHS as described in claim 7, wherein the distributed secure communication engine is configured to: Monitor the SCP subsystem and, in response, identify the second SCP subsystem.

9. The IHS as described in claim 7, wherein the distributed secure communication engine is configured to: The second public key associated with the second SCP subsystem is retrieved via the network.

10. The IHS of claim 7, wherein the distributed secure communication engine is configured to: First control communication with the second SCP subsystem is transmitted via the first secure communication channel; and The second control communication with the third SCP subsystem is transmitted through the third secure communication channel.

11. The IHS of claim 10, wherein the distributed secure communication engine is configured to: First data communication with the second SCP subsystem is transmitted via a first insecure communication channel; and Second data communication with the third SCP subsystem is transmitted via a second insecure communication channel.

12. The IHS of claim 7, wherein the proof of the authentication of the third SCP subsystem comprises: A third public key, which is associated with the third SCP subsystem; as well as Third SCP subsystem communication connection information.

13. The IHS as described in claim 7, wherein the distributed secure communication engine is configured to: The authentication certificate for the fourth SCP subsystem is received from the third SCP subsystem via the second secure communication channel. The fourth SCP subsystem has established a fourth secure communication channel between the third SCP subsystem and the fourth SCP subsystem. In response, a fifth secure communication channel is established with the fourth SCP subsystem without performing the signed secure communication channel establishment process with the fourth SCP subsystem.

14. A method for providing distributed secure communication, comprising: The first system control processor (SCP) subsystem identifies the second SCP subsystem and, in response, executes a signed secure communication channel establishment procedure with the second SCP subsystem, including: The first SCP authentication communication is signed with the first private key to provide the first signed SCP authentication communication; The first SCP subsystem transmits the first signed SCP authentication communication to the second SCP subsystem; The first SCP subsystem receives a second signed SCP authentication communication from the second SCP subsystem, and in response, authenticates the second signed SCP authentication communication using a second public key associated with the second SCP subsystem. In response to authenticating the second signed SCP authentication communication, a first secure communication channel is established between the first SCP subsystem and the second SCP subsystem; Through the first secure communication channel, the first SCP subsystem receives proof of authentication for the third SCP subsystem from the second SCP subsystem, which has established a second secure communication channel between the second SCP subsystem and the third SCP subsystem, and in response, establishes a third secure communication channel with the third SCP subsystem without performing the signed secure communication channel establishment process with the third SCP subsystem.

15. The method of claim 14, further comprising: The first SCP subsystem monitors the SCP subsystem and, in response, identifies the second SCP subsystem.

16. The method of claim 14, further comprising: The first SCP subsystem retrieves the second public key associated with the second SCP subsystem via the network.

17. The method of claim 14, further comprising: The first control communication between the first SCP subsystem and the second SCP subsystem is transmitted through the first secure communication channel. and The first SCP subsystem transmits second control communication with the third SCP subsystem via the second secure communication channel.

18. The method of claim 17, further comprising: The first data communication between the first SCP subsystem and the second SCP subsystem is transmitted through a first insecure communication channel. and The first SCP subsystem transmits second data communication with the third SCP subsystem via a second insecure communication channel.

19. The method of claim 14, wherein the proof of the authentication of the third SCP subsystem comprises: A third public key, which is associated with the third SCP subsystem; as well as Third SCP subsystem communication connection information.

20. The method of claim 14, further comprising: Through the second secure communication channel, the first SCP subsystem receives proof of authentication for the fourth SCP subsystem from the third SCP subsystem, which has established a fourth secure communication channel between the third SCP subsystem and the fourth SCP subsystem. In response, a fifth secure communication channel is established with the fourth SCP subsystem without performing the signed secure communication channel establishment process with the fourth SCP subsystem.

Citation Information

Patent Citations

  • Platform root-of-trust system

    US11907386B2

  • Distributed key management system

    US20220123920A1

  • Identity authentication method, server and authentication terminal

    CN105515783A

  • System for digital identity authentication and methods of use

    US20190149334A1