Master Adapter Device for Secure Bare-Metal Server Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Bare-metal instances in compute service systems pose a security risk due to direct client access to server hardware, allowing potential interference with management or configuration, which can render servers unavailable or less useful to other customers.

Innovation Solution

A secure internal management network is established using a master adapter device to manage and isolate server components, controlling access and preventing unauthorized network packets from entering the internal Ethernet network, thereby protecting server components from potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If bare-metal instances provide direct client access to server hardware, then client control and performance are improved, but security risks increase allowing potential interference with management or configuration

Engineering Contradiction:
Improveclient controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the network into two distinct parts: an internal management network for server control and an external network for client access. This segmentation isolates the management functions from direct client access, allowing bare-metal performance while preventing unauthorized interference with server configuration and management operations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a hypervisor is introduced to manage virtual machines, then security is improved by isolating client access, but performance overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidperformance overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security function from the traditional hypervisor model by implementing network-level isolation through adapter devices and internal management networks. This allows bare-metal instances to run without hypervisor overhead while maintaining security through network segmentation and controlled access paths.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If direct hardware access is provided to clients, then performance is improved by eliminating hypervisor overhead, but security risks increase allowing unauthorized access to server components

Engineering Contradiction:
ImproveperformanceVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system introduces adapter devices as intermediaries between client access points and server components. These adapter devices control and filter network traffic, allowing legitimate performance-critical operations while blocking unauthorized access attempts to management and configuration functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10911405B1Secure environment on a server
Publication Date: 2021.02.02 AMAZON TECH INC
  • US10911405B1 patent drawing
  • US10911405B1 patent drawing
  • US10911405B1 patent drawing

AI summary

Disclosed herein are techniques for maintaining a secure environment on a server. In one embodiment, the server includes a baseboard management controller (BMC), a first Ethernet port coupled with an adapter device network comprising a plurality of adapter devices, and a master adapter device including a second Ethernet port and a network switch, the network switch being controllable to be selectively coupled with at least one of the BMC, the first Ethernet port, or the second Ethernet port. The master adapter device may receive a network packet from at least one of: the first Ethernet port, the second Ethernet port, or the BMC, and determine, based on a forwarding policy, whether to forward the network packet. Based on a determination to forward the network packet, the master adapter device may determine a destination, and control the network switch to transmit the network packet to the destination.