Blade Server Cryptographic Affinity for Cluster Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared computing clusters, conventional cryptographic schemes often lock out shared drives with multiple keys, compromising security and availability, as they are based on baseboard and chassis management controllers rather than individual blade servers and network interfaces.

Innovation Solution

Implementing cryptographic key management that binds individual blade servers to their network interfaces using host bus adapters (HBAs), generating a cryptographic affinity based on blade and HBA identifiers to secure data access and ensure authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cryptographic schemes based on baseboard and chassis management controllers are used, then shared drives can be accessed by multiple servers, but security is compromised because the entire chassis may be locked out

Engineering Contradiction:
ImprovesecurityVSAvoidavailability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the cryptographic key management from the chassis level to the individual blade level. Each blade server receives unique cryptographic keys bound to its specific network interface card, rather than using a single chassis-wide key. This segmentation allows individual blades to access shared storage independently without affecting other blades, resolving the contradiction between security and availability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic keys are bound to individual blade servers and network interfaces, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary cryptographic key binding during the initialization phase, where each blade server's cryptographic identity is bound to its network interface card before the server begins operational workloads. This preliminary action establishes secure access credentials in advance, simplifying subsequent key management operations and reducing runtime complexity while maintaining enhanced security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If shared storage is accessed using traditional cryptographic methods, then storage capacity can be shared among servers, but the entire chassis may be locked out compromising availability

Engineering Contradiction:
Improvestorage sharingVSAvoidavailability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by providing each blade server with locally-specific cryptographic credentials bound to its individual network interface card. This allows each blade to independently authenticate and access shared storage resources without interfering with other blades' access. The local cryptographic binding resolves the contradiction between storage sharing capability and system availability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10728030B2System and method for key management in computing clusters
Publication Date: 2020.07.28 DELL PROD LP
  • US10728030B2 patent drawing
  • US10728030B2 patent drawing
  • US10728030B2 patent drawing

AI summary

Cryptographic affinities are generated to improve security in server environments. One or more cryptographic affinities protect electronic data stored within a blade server. The cryptographic affinities are generated based on hashing a unique blade identifier and a unique identifier assigned to a network interface. The cryptographic affinities thus govern read, write, and other access operations. If any cryptographic affinity fails to match historical observance, then access to the blade server may be denied.