Chassis-Based Cryptographic Affinities for Blade Server Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems face challenges in ensuring the security and integrity of data stored on blade servers, particularly when these servers are moved from one chassis to another, as existing solutions lack effective mechanisms to prevent unauthorized access.
Innovation Solution
Implementing a cryptographic affinity system where each blade server is cryptographically tied to a specific chassis, group of chassis, or data center, using a chassis management controller to generate and verify cryptographic signatures, ensuring access is restricted if the server is moved to an unauthorized location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If blade servers are allowed to be freely moved between chassis, then ease of operation and flexibility are improved, but data security and integrity deteriorate
Solution Approach 1:
The system performs preliminary cryptographic binding between the blade server and chassis before any data access occurs. The chassis management controller generates a cryptographic affinity by combining the blade server's unique identifier with the chassis's unique identifier, creating a pre-established security relationship that must be satisfied before the server can access stored data.
Solution Approach 2:
The chassis management controller acts as an intermediary between the blade server and the data storage system. It manages the cryptographic affinity by verifying that the blade server presents the correct cryptographic binding corresponding to the specific chassis before allowing data access, thus mediating the trust relationship.
2Reliability
If cryptographic affinity is enforced between blade server and chassis, then data security is improved, but device complexity increases
Solution Approach 1:
The system merges the cryptographic affinity verification function into the existing chassis management controller, combining security functions with the existing management infrastructure. This integration approach avoids adding separate complex security hardware by embedding the cryptographic verification within the existing controller's functionality.
Solution Approach 2:
The system uses cryptographic hashes and digital signatures that create a mathematical copy of the binding relationship between server and chassis identifiers. This allows verification of affinity without requiring physical or complex structural binding mechanisms, simplifying the implementation while maintaining security.
Data Source
AI summary
Cryptographic affinities are generated to improve security in data centers. When a blade server is hot swapped, the cryptographic affinities protect electronic data stored within the blade server. The cryptographic affinities are generated based on hashing a unique chassis identifier. If the blade server is installed in a different chassis, the cryptographic affinities lock out the different chassis from read, write, and other access operations. The cryptographic affinities may even require deleting or reformatting before rekeying is commenced.


