Modular Chassis Trusted Groups for Blade Pre-Boot Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems lack a centralized method to manage and authenticate the pre-boot process for modular chassis, requiring IT administrators to manually manage BIOS passwords for each blade server and lack detection and prevention of unauthorized blade insertions and relocations.
Innovation Solution
A modular chassis management resource is provisioned with a centralized, integrated pre-boot authentication intelligence that generates and maintains unique security key information for each blade server, allowing automatic authentication within a logical trusted group and manual authentication for new blades.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual BIOS password management is used for each blade server, then authentication security is maintained, but administrative workload and time consumption increase significantly
Solution Approach 1:
The patent combines multiple blade servers into a logical trusted group where a single pre-boot authentication credential protects all members. The chassis management controller coordinates authentication across the group, merging individual authentication processes into a unified system that reduces administrative overhead while maintaining security.
Solution Approach 2:
The pre-boot authentication credential serves multiple functions: it authenticates individual blade servers, protects against unauthorized insertions, enables automatic re-authentication for relocated blades, and provides centralized management capability. This multi-functional approach eliminates the need for separate credentials for each blade.
2Ease of operation
If centralized pre-boot authentication is implemented, then administrative workload is reduced, but system complexity and infrastructure requirements increase
Solution Approach 1:
The chassis management controller acts as an intermediary between blade servers and authentication credentials. It stores credentials securely, coordinates authentication requests, and manages the trusted group database. This intermediary approach centralizes management functionality without requiring complex changes to individual blade servers or external authentication servers.
3Reliability
If BIOS password tokens are used for pre-boot authentication, then security is provided, but manual configuration for each blade is required which is cumbersome
Solution Approach 1:
The system performs preliminary actions by pre-configuring the logical trusted group and storing authentication credentials in the chassis management controller before blade servers are inserted or relocated. When a blade is inserted into a trusted group slot, authentication is automatically enabled without requiring manual configuration, as the credential is already in place and the blade's identity is registered in advance.
4Adaptability or versatility
If conventional modular chassis management is used, then basic functionality is provided, but detection and prevention of unauthorized blade insertions and relocations is lacking
Solution Approach 1:
The system implements feedback mechanisms where the chassis management controller continuously monitors blade server positions and identities. When a blade is inserted or relocated, the controller detects the change, verifies the blade's identity against the trusted group database, and either automatically authenticates or blocks access based on the verification result. This closed-loop feedback ensures security while maintaining operational flexibility.
Data Source
AI summary
Disclosed methods maintain security key information, including a unique security key, for one or more blade servers inserted in slots of one or more modular chassis. Following an indication of a logical trusted group comprising a plurality of slots, a trusted group database, including the security key information for each blade server in a slot of the trusted group, is maintained. Responsive to detecting movement of a blade server between two slots of the trusted group, a pre boot process of the server blade in the second slot is automatically authenticated via the security key information in the trusted group database. If a blade server not associated with the trusted group is inserted into a trusted group slot, automatic authentication is blocked and the user is prompted to manually authenticate the new blade server. If manual authentication is successful, security key information for the new blade is added to the database.


