BMC Secure Certificate Storage for Data Center Asset Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based data center management systems face challenges with one-way communication channels hindered by firewalls, proxies, and complex network setups, necessitating an always-connected, bidirectional connection for real-time management of data center assets.
Innovation Solution
A method and system for establishing a secure communication channel between a data center asset client module and a connectivity management system, involving attestation and proof of ownership information exchange, using a connectivity management system aggregator and service to facilitate bidirectional communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud-based data center management systems use traditional one-way communication channels, then system simplicity is maintained, but real-time bidirectional management capability is lost
Solution Approach 1:
The patent introduces a Baseboard Management Controller (BMC) as an intermediary component that establishes a secure communication channel between the data center asset and the cloud-based management system. The BMC acts as a mediator that enables bidirectional real-time communication while maintaining system security and managing the complexity of direct peer-to-peer connections between the management console and the asset.
2Ease of operation
If digital certificates are stored in the operating system, then ease of access is improved, but security is compromised due to code disassembly risks
Solution Approach 1:
The patent segments the system into two distinct parts for certificate storage: the BMC (a hardware-based secure component) and the operating system. The digital certificates are stored in the BMC rather than the OS, separating the security-critical certificate storage function from the general-purpose OS environment. This segmentation allows the certificates to remain secure in the BMC while still being accessible when needed through controlled interfaces.
Solution Approach 2:
The BMC serves as an intermediary that securely holds digital certificates and selectively provides them to the OS or management system when authentication is required. This mediator approach allows the certificates to remain protected in the BMC while still enabling authentication functions, thus maintaining both security and operational capability.
3Reliability
If firewalls and proxies are used to secure cloud-based communication, then security is improved, but communication reliability and real-time connectivity deteriorate
Solution Approach 1:
The patent implements preliminary authentication and secure channel establishment actions before actual data management operations begin. The BMC establishes a secure communication channel in advance using digital certificates, and the system performs authentication sequences beforehand to ensure that subsequent real-time bidirectional communications can occur without being blocked or interfered with by firewalls and proxies.
Data Source
AI summary
A system, method, and computer-readable medium for performing a data center monitoring and management operation. The data center monitoring and management operation includes: providing a data center asset with a data center asset client module; establishing a connection between the data center asset client module and a connectivity management system of a data center monitoring and management console, the connectivity management system comprising a connectivity management system aggregator and a connectivity management system service; exchanging attestation and proof of ownership information between the data center asset communication client module and the connectivity management system service of the connectivity management system; establishing a secure communication channel between the data center asset client module and the connectivity management system aggregator based upon the attestation and proof of ownership information; and, exchanging information between the data center asset client module and the data center monitoring and management console via the secure communication channel between the data center asset client module and the connectivity management system aggregator.


