BMC Passthrough Mechanism for SED Security Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional host bus adapters (HBAs) are unable to securely manage and implement the necessary security methods for self-encrypting drives (SEDs), necessitating an additional agent like a baseboard management controller (BMC) to handle the security and life cycle management of SEDs.
Innovation Solution
The method involves identifying a self-encrypting drive on a computing device and unlocking it using a BMC, which then registers the drive with the operating system, with the BMC managing access and security through a passthrough mechanism with the HBA, utilizing key management services to generate and store encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional host bus adapters (HBAs) are used to manage storage devices, then the storage system is simple in structure, but the HBA cannot securely manage self-encrypting drives (SEDs) and implement necessary security methods
Solution Approach 1:
The patent introduces a baseboard management controller (BMC) as an intermediary component between the HBA and SEDs. The BMC acts as a mediator that handles security operations (unlocking, key management) for SEDs, while the HBA continues to manage storage operations. This intermediary approach enables secure SED management without requiring the HBA to have complex security capabilities, thus resolving the contradiction between security reliability and system simplicity.
2Reliability
If a BMC is added to manage SEDs, then security and life cycle management of SEDs is improved, but the device complexity increases
Solution Approach 1:
The BMC is designed to perform multiple functions beyond just SED management, including system monitoring, firmware updates, and general hardware control. By making the BMC a multi-functional component, the patent justifies the added complexity through enhanced versatility. The BMC handles both SED security operations and other system management tasks, making the increased device complexity worthwhile through improved overall system management capabilities.
3Ease of manufacture
If security operations are handled by the HBA, then the system has fewer components, but the HBA cannot implement necessary security methods for SEDs
Solution Approach 1:
The patent segments the storage management system into distinct functional components: the HBA handles storage operations while the BMC handles security operations. This segmentation allows each component to be optimized for its specific function - the HBA for storage efficiency and the BMC for security capabilities. By dividing responsibilities, the system achieves both ease of manufacture (each component can be independently optimized and manufactured) and reliable security implementation (BMC has dedicated security capabilities).
Data Source
AI summary
In general, embodiments of the invention relate to a method and system for managing a storage system. In many traditional implementations host bus adapter (HBA) manages the storage device, however frequently the HBA cannot implement the necessary methods to secure a self-encrypting drive (SED). One or more embodiments of the invention use a baseboard management controller (BMC) to manage the security of the SEDs as well as the security life cycle of the SEDs, while the HBA acts as a passthrough conduit between the SED and BMC.


