Chassis-Based Cryptographic Affinities for Blade Server Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in ensuring the security and integrity of data stored on blade servers, particularly when these servers are moved from one chassis to another, as existing solutions lack effective mechanisms to prevent unauthorized access.

Innovation Solution

Implementing a cryptographic affinity system where each blade server is cryptographically tied to a specific chassis, group of chassis, or data center, using a chassis management controller to generate and verify cryptographic signatures, ensuring access is restricted if the server is moved to an unauthorized location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If blade servers are allowed to be freely moved between chassis, then ease of operation and flexibility are improved, but data security and integrity deteriorate

Engineering Contradiction:
Improveflexibility of server movementVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary cryptographic binding between the blade server and chassis before any data access occurs. The chassis management controller generates a cryptographic affinity by combining the blade server's unique identifier with the chassis's unique identifier, creating a pre-established security relationship that must be satisfied before the server can access stored data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The chassis management controller acts as an intermediary between the blade server and the data storage system. It manages the cryptographic affinity by verifying that the blade server presents the correct cryptographic binding corresponding to the specific chassis before allowing data access, thus mediating the trust relationship.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic affinity is enforced between blade server and chassis, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidcryptographic binding mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the cryptographic affinity verification function into the existing chassis management controller, combining security functions with the existing management infrastructure. This integration approach avoids adding separate complex security hardware by embedding the cryptographic verification within the existing controller's functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system uses cryptographic hashes and digital signatures that create a mathematical copy of the binding relationship between server and chassis identifiers. This allows verification of affinity without requiring physical or complex structural binding mechanisms, simplifying the implementation while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10355861B2Chassis-based cryptographic affinities
Publication Date: 2019.07.16 DELL PROD LP
  • US10355861B2 patent drawing
  • US10355861B2 patent drawing
  • US10355861B2 patent drawing

AI summary

Cryptographic affinities are generated to improve security in data centers. When a blade server is hot swapped, the cryptographic affinities protect electronic data stored within the blade server. The cryptographic affinities are generated based on hashing a unique chassis identifier. If the blade server is installed in a different chassis, the cryptographic affinities lock out the different chassis from read, write, and other access operations. The cryptographic affinities may even require deleting or reformatting before rekeying is commenced.