Master Adapter Device for Secure Bare-Metal Server Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bare-metal instances in compute service systems pose a security risk due to direct client access to server hardware, allowing potential interference with management or configuration, which can render servers unavailable or less useful to other customers.
Innovation Solution
A secure internal management network is established using a master adapter device to manage and isolate server components, controlling access and preventing unauthorized network packets from entering the internal Ethernet network, thereby protecting server components from potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If bare-metal instances provide direct client access to server hardware, then client control and performance are improved, but security risks increase allowing potential interference with management or configuration
Solution Approach 1:
The system segments the network into two distinct parts: an internal management network for server control and an external network for client access. This segmentation isolates the management functions from direct client access, allowing bare-metal performance while preventing unauthorized interference with server configuration and management operations.
2Reliability
If a hypervisor is introduced to manage virtual machines, then security is improved by isolating client access, but performance overhead increases
Solution Approach 1:
The patent extracts the security function from the traditional hypervisor model by implementing network-level isolation through adapter devices and internal management networks. This allows bare-metal instances to run without hypervisor overhead while maintaining security through network segmentation and controlled access paths.
3Productivity
If direct hardware access is provided to clients, then performance is improved by eliminating hypervisor overhead, but security risks increase allowing unauthorized access to server components
Solution Approach 1:
The system introduces adapter devices as intermediaries between client access points and server components. These adapter devices control and filter network traffic, allowing legitimate performance-critical operations while blocking unauthorized access attempts to management and configuration functions.
Data Source
AI summary
Disclosed herein are techniques for maintaining a secure environment on a server. In one embodiment, the server includes a baseboard management controller (BMC), a first Ethernet port coupled with an adapter device network comprising a plurality of adapter devices, and a master adapter device including a second Ethernet port and a network switch, the network switch being controllable to be selectively coupled with at least one of the BMC, the first Ethernet port, or the second Ethernet port. The master adapter device may receive a network packet from at least one of: the first Ethernet port, the second Ethernet port, or the BMC, and determine, based on a forwarding policy, whether to forward the network packet. Based on a determination to forward the network packet, the master adapter device may determine a destination, and control the network switch to transmit the network packet to the destination.


