BMC Secure Certificate Storage for Data Center Asset Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based data center management systems face challenges with one-way communication channels hindered by firewalls, proxies, and complex network setups, necessitating an always-connected, bidirectional connection for real-time management of data center assets.

Innovation Solution

A method and system for establishing a secure communication channel between a data center asset client module and a connectivity management system, involving attestation and proof of ownership information exchange, using a connectivity management system aggregator and service to facilitate bidirectional communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud-based data center management systems use traditional one-way communication channels, then system simplicity is maintained, but real-time bidirectional management capability is lost

Engineering Contradiction:
Improvereal-time management capabilityVSAvoidcommunication channel complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a Baseboard Management Controller (BMC) as an intermediary component that establishes a secure communication channel between the data center asset and the cloud-based management system. The BMC acts as a mediator that enables bidirectional real-time communication while maintaining system security and managing the complexity of direct peer-to-peer connections between the management console and the asset.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If digital certificates are stored in the operating system, then ease of access is improved, but security is compromised due to code disassembly risks

Engineering Contradiction:
Improvecertificate access便利性VSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the system into two distinct parts for certificate storage: the BMC (a hardware-based secure component) and the operating system. The digital certificates are stored in the BMC rather than the OS, separating the security-critical certificate storage function from the general-purpose OS environment. This segmentation allows the certificates to remain secure in the BMC while still being accessible when needed through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The BMC serves as an intermediary that securely holds digital certificates and selectively provides them to the OS or management system when authentication is required. This mediator approach allows the certificates to remain protected in the BMC while still enabling authentication functions, thus maintaining both security and operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls and proxies are used to secure cloud-based communication, then security is improved, but communication reliability and real-time connectivity deteriorate

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidfirewall and proxy interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and secure channel establishment actions before actual data management operations begin. The BMC establishes a secure communication channel in advance using digital certificates, and the system performs authentication sequences beforehand to ensure that subsequent real-time bidirectional communications can occur without being blocked or interfered with by firewalls and proxies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11997073B2Secure certificate storage when a connectivity management system client is running on an operating system
Publication Date: 2024.05.28 DELL PROD LP
  • US11997073B2 patent drawing
  • US11997073B2 patent drawing
  • US11997073B2 patent drawing

AI summary

A system, method, and computer-readable medium for performing a data center monitoring and management operation. The data center monitoring and management operation includes: providing a data center asset with a data center asset client module; establishing a connection between the data center asset client module and a connectivity management system of a data center monitoring and management console, the connectivity management system comprising a connectivity management system aggregator and a connectivity management system service; exchanging attestation and proof of ownership information between the data center asset communication client module and the connectivity management system service of the connectivity management system; establishing a secure communication channel between the data center asset client module and the connectivity management system aggregator based upon the attestation and proof of ownership information; and, exchanging information between the data center asset client module and the data center monitoring and management console via the secure communication channel between the data center asset client module and the connectivity management system aggregator.