Dynamic External I/O Port Screening via Out-of-Band Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face security vulnerabilities through external input/output ports, which can be compromised by unauthorized devices, and existing management approaches are cumbersome, requiring rebooting and BIOS settings changes to enable or disable ports, without allowing discrimination among device classes.
Innovation Solution
An information handling system with a processor, external I/O ports, a chipset including an I/O port controller, and a management controller that provides out-of-band management to dynamically enable or disable individual external I/O ports based on a port security policy, independent of the system's operating state, allowing for real-time screening and selective enablement of specific device classes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external I/O ports are disabled to improve security, then security vulnerability is reduced, but ease of operation deteriorates as administrators cannot enable ports when needed without rebooting
Solution Approach 1:
The patent implements dynamic port enablement where the management controller can change the enabled/disabled state of I/O ports in real-time based on authentication, without requiring system reboot. This transforms the static port configuration into a dynamic one that adapts to current security requirements and user needs.
Solution Approach 2:
The management controller acts as an intermediary between the processor and I/O ports, providing out-of-band management capability. This intermediary can authenticate users and control port states independently of the host system's operating state, resolving the conflict between security and operational flexibility.
2Reliability
If BIOS menu options are used to control I/O ports, then security can be managed, but loss of time increases due to required reboots and administrator intervention
Solution Approach 1:
The management controller pre-authenticates users and pre-configures port states before actual I/O operations are needed. This preliminary authentication and configuration eliminates the need for time-consuming reboots and sequential administrator interventions when ports need to be enabled during system operation.
Solution Approach 2:
The system maintains continuous port management capability through the management controller, which can enable or disable ports at any time without interrupting system operation or requiring reboots. This ensures continuous useful action in both security management and port accessibility.
3Reliability
If all external ports are disabled by default, then security is improved, but adaptability deteriorates as the system cannot respond to different device classes dynamically
Solution Approach 1:
The patent applies different security policies to different I/O ports and device classes individually. Instead of a blanket enable/disable approach, each port can have its own authentication requirements and device class restrictions, allowing the system to be security-conscious while remaining adaptable to specific device needs.
Solution Approach 2:
The system dynamically changes port state parameters (enabled/disabled) based on authentication results and device class identification. This parameter change capability allows the system to adapt its security posture in real-time based on the specific device being connected and the authenticated user's permissions.
Data Source
AI summary
In accordance with embodiments of the present disclosure, an information handling system may include a host system comprising a processor, one or more external input/output (I/O) ports, a chipset communicatively coupled to the processor and including an I/O port controller, the I/O port controller interfacing between the processor and the one or more external I/O ports, and a management controller communicatively coupled to the processor configured to provide out-of-band management of the information handling system, and further configured to communicate a port security policy to a component of the chipset such that the I/O port controller dynamically enables and disables, independent of an operating state of the host system, individual ones of the one or more external I/O ports in accordance with the port security policy.

