BMC Ownership Certificate Overlay for Secure Data Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in automatic ownership reversion, secure data erasure, and configuration reversion at the end of a leasing period, leading to potential exposure of confidential data and access issues when ownership is transferred among multiple users.
Innovation Solution
An information handling system with a baseboard management controller (BMC) that configures and manages ownership certificates, allowing for automatic reversion of ownership, secure erasure of data, and reversion to previous configurations by storing and overlaying signed provisioning configuration contents based on ownership certificates, ensuring seamless transitions between owners.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ownership certificates are transferred among multiple users in an information handling system, then the system can be shared and utilized by different owners, but security risks arise when previous owners retain access or residual data remains on the system
Solution Approach 1:
The system performs automatic data erasure and configuration reversion as a preliminary action when an ownership certificate expires or is revoked. The BMC detects the expiration event and automatically executes the erasure of provisioning configuration content and reversion to previous configurations before the next owner can access the system, thereby preventing security risks from residual data
Solution Approach 2:
The Baseboard Management Controller (BMC) acts as an intermediary between the ownership certificate management and the provisioning configuration content. The BMC monitors certificate validity, detects expiration events, and mediates the automatic erasure and reversion processes, ensuring secure transitions between owners without requiring manual intervention
2Extent of automation
If manual processes are used for ownership transfer, data erasure, and configuration reversion, then system complexity is reduced, but time consumption increases and automatic reversion cannot be achieved at the end of leasing periods
Solution Approach 1:
The system implements a feedback mechanism where the BMC continuously monitors the validity status of ownership certificates. When a certificate expires or is revoked, the BMC receives feedback about this event and automatically triggers the data erasure and configuration reversion processes, enabling automatic ownership reversion without manual intervention
Solution Approach 2:
The information handling system performs self-service by automatically detecting certificate expiration events and executing the complete ownership transfer process including data erasure and configuration reversion. The system serves itself by monitoring its own state and initiating corrective actions without external intervention, significantly reducing time consumption
3Ease of operation
If provisioning configuration content is stored in accessible memory, then configuration updates are easy to apply, but confidential data may be exposed when ownership is transferred
Solution Approach 1:
The system extracts and selectively erases provisioning configuration content from memory when an ownership certificate expires. The BMC identifies and removes the specific confidential data associated with the expired owner while preserving the ability to restore previous configurations, thereby preventing exposure of confidential data during ownership transfers
Data Source
AI summary
An information handling system includes a provisioning server and a server. The server includes a baseboard management controller (BMC) that configures a first ownership certificate for the server, and provides it to the provisioning server. The first ownership certificate is associated with a first owner. The BMC receives a first signed provisioning configuration content, and stores the first signed provisioning configuration content in an encrypted memory. The BMC configures a second ownership certificate for the server, and provides it to the provisioning server. The second ownership certificate is associated with a second owner. The BMC receives a second signed provisioning configuration content, and stores the second signed provisioning configuration content on top of the first signed provisioning configuration content in the encrypted memory. In response to an expiration of the second ownership certificate, the BMC removes the first signed provisioning configuration content, and applies the second signed provisioning configuration content.


