BMC Key Vault for Secure VM Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data encryption key management systems face challenges such as unavailability issues, vendor-specific configurations, complexity in multi-site environments, and difficulties in maintaining key management systems with additional security measures like TPMs and HSMs, particularly in cloud and local key management solutions.

Innovation Solution

The proposed solution involves an Information Handling System (IHS) that utilizes a Baseboard Management Controller (BMC) engine to manage data encryption keys, storing them in a key vault and facilitating secure retrieval and transmission, allowing for vendor-agnostic key management and operation during pre-boot environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cloud key management solutions are used, then key management is centralized and accessible, but system availability decreases when key management server devices are unavailable

Engineering Contradiction:
Improvekey management availabilityVSAvoidexternal key management system dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BMC acts as an intermediary key management component between the host system and external key management systems. It maintains a local key vault that stores data encryption keys, allowing the system to access keys locally when external systems are unavailable, thereby improving reliability while maintaining the ability to integrate with external key management infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional local key management solutions are used, then key access is simple and direct, but vendor-specific configurations increase system complexity

Engineering Contradiction:
Improvekey access simplicityVSAvoidvendor-specific configuration requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The BMC key management solution provides a universal, vendor-agnostic platform that can manage keys for multiple operating systems and virtualization environments. The BMC firmware and key vault implementation are not tied to specific vendors, allowing the same infrastructure to support different OS types and virtualization platforms without requiring vendor-specific configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If additional security measures like TPMs and HSMs are implemented, then security is enhanced, but key maintenance complexity increases

Engineering Contradiction:
Improvesecurity strengthVSAvoidkey maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The solution merges the key management functionality directly into the BMC firmware and integrates with existing BMC security features rather than adding separate TPM or HSM hardware. The BMC's built-in security mechanisms and key vault provide the necessary security protections while maintaining centralized control through the management console, reducing maintenance complexity compared to managing multiple separate security hardware components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11599378B2Data encryption key management system
Publication Date: 2023.03.07 DELL PROD LP
  • US11599378B2 patent drawing
  • US11599378B2 patent drawing
  • US11599378B2 patent drawing

AI summary

A data encryption key management system includes an application layer with a hypervisor and a virtual machine, a host operating system coupled to the application layer and including a key management agent, and a Baseboard Management Controller (BMC) device coupled to the host operating system and including a BMC storage device providing a key vault. The BMC device receives a first stored data encryption key that was generated by the hypervisor for the virtual machine from the key management agent, and stores the first stored data encryption key in the key vault provided by the BMC storage device. The BMC device subsequently receives a stored data encryption key request from the key management agent and, in response, retrieves the first stored data encryption key from the key vault provided by the BMC storage device, and transmits the first stored data encryption key to the key management agent.