Baseboard Management Controller Internet Access Restriction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices with remote management capabilities connected to the Internet are vulnerable to security threats due to inherent flaws in protocols and default settings, which can lead to insecure access and attacks from external entities, exacerbated by the Internet of Things (IoT) trend.

Innovation Solution

A baseboard management controller (BMC) determines whether it has access to the Internet and takes security actions, such as disabling vulnerable protocols, limiting packet communication, and changing default passwords, to mitigate these risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If devices with remote management capabilities are connected to the Internet, then remote management functionality is improved, but security vulnerabilities are exacerbated

Engineering Contradiction:
Improveremote management capabilityVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network interface controller as an intermediary component between the Internet and the baseboard management controller. This intermediary monitors network traffic and implements security policies, allowing remote management functionality while filtering out malicious attacks before they reach the vulnerable BMC protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct zones: a public Internet-facing network interface, a protected management network for BMC communications, and isolation mechanisms between them. This segmentation allows Internet connectivity for device management while preventing direct exposure of vulnerable BMC protocols to external threats.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If vulnerable protocols are enabled for remote access, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improveprotocol accessibilityVSAvoidsecurity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic protocol enabling/disabling based on network conditions and security policies. The system can dynamically enable vulnerable protocols only when accessed through secure channels (e.g., internal network), while automatically disabling them when Internet access is detected, thus adapting protocol availability to security requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the operational parameters of protocols based on network context. It monitors network interface status and dynamically adjusts protocol configuration parameters, such as enabling SSL/TLS encryption for Internet-accessible interfaces while allowing unencrypted protocols only on isolated management networks, thereby maintaining functionality while improving security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10944719B2Restrict communications to device based on internet access
Publication Date: 2021.03.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10944719B2 patent drawing
  • US10944719B2 patent drawing
  • US10944719B2 patent drawing

AI summary

Examples disclosed herein relate to securing a controller of a device. The controller is to determine whether a network interface of the device is connected to the Internet. Communications are restricted on the network interface in response to the port having access to the Internet. In some examples, the restriction can be related to a vulnerability.