Dynamic IPMI Credentials via Hash Chains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote management interfaces, such as IPMI, suffer from security deficiencies like reliance on static passwords and vulnerability to offline password-guessing attacks, which can lead to unauthorized access and increased risk due to weak passwords and shared credentials across multiple devices.
Innovation Solution
Implementing a remote management interface that uses credentials associated with access control intervals, generated based on hash chains and message authentication codes, eliminating the need for static passwords and preventing offline password-guessing attacks by incorporating dynamic credentials into IPMI protocol messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static passwords are used in IPMI, then ease of operation is improved, but security is worsened due to vulnerability to offline password-guessing attacks
Solution Approach 1:
The patent replaces static passwords with dynamic credentials that change over time. The system uses a credential validity period mechanism where credentials are periodically updated, making them time-dependent rather than static. This allows the system to maintain ease of operation while eliminating offline password-guessing attacks, as each credential is valid only for a limited period and cannot be reused.
Solution Approach 2:
The patent changes the parameter of credential validity from infinite (static) to limited time period (dynamic). By introducing a credential validity period parameter, the system transforms the security model from static passwords to time-limited credentials. This parameter change enables the system to address both ease of operation and security requirements simultaneously.
2Ease of operation
If shared passwords are used across multiple devices, then ease of operation is improved, but security is worsened due to increased attack surface and credential reuse vulnerability
Solution Approach 1:
The patent segments the credential system by assigning unique credentials to each device rather than using shared passwords. Each device has its own credential set that is independently managed and validated. This segmentation approach maintains ease of operation through centralized credential management while eliminating the security risks associated with shared credentials across multiple devices.
3Ease of operation
If IPMI protocol is used for remote management, then ease of operation is improved, but security is worsened due to inherent protocol vulnerabilities
Solution Approach 1:
The patent introduces a credential validation intermediary mechanism between the remote management interface and the authentication process. This intermediary layer handles the credential verification, validity period checking, and security protocols, allowing the IPMI protocol to maintain its ease of operation while adding security through the intermediary credential validation layer.
Data Source
AI summary
A processing device comprises a processor coupled to a memory and is configured to obtain a credential associated with a particular access control interval, to insert information derived from the credential into one or more messages of a remote management interface protocol, to transmit the one or more messages to a managed device, and to remotely control the managed device responsive to a successful authentication based at least in part on the inserted information. The one or more messages of the remote management interface protocol are illustratively compliant with a designated Intelligent Platform Management Interface (IPMI) specification. The credential associated with the particular access control interval may be generated based at least in part on a corresponding intermediate value of a hash chain. For example, the credential may be generated based at least in part on a message authentication code and the corresponding intermediate value of a hash chain.


