Multi-Port Hardware Component Protection via Secure Credential Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware devices with both in-band and out-of-band management capabilities are vulnerable to malicious exploitation, as existing security measures fail to effectively control and manage privileged commands on these paths, leading to potential unauthorized access and malicious acts.
Innovation Solution
A method that configures user commands on multiple ports of a processing device to enabled or disabled states, sharing credentials securely through a basic input/output system to control and manage in-band and out-of-band paths, ensuring that only authorized commands are executed and preventing unauthorized access by locking or unlocking command states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If in-band and out-of-band management capabilities are enabled for hardware devices, then management flexibility and control are improved, but security vulnerabilities increase due to potential malicious exploitation
Solution Approach 1:
The patent segments the management paths into in-band and out-of-band channels, applying distinct security policies and credential verification mechanisms to each path. This segmentation allows the system to maintain management flexibility while addressing security vulnerabilities through path-specific controls.
Solution Approach 2:
The patent introduces an intermediary credential sharing mechanism between the in-band and out-of-band management paths. This intermediary system verifies credentials and enforces security policies, allowing both management paths to function while preventing malicious exploitation through centralized security control.
2Ease of operation
If privileged commands are allowed on both in-band and out-of-band paths, then operational capability is improved, but unauthorized access risk increases
Solution Approach 1:
The patent implements preliminary credential verification and command authorization before executing privileged commands on either in-band or out-of-band paths. By pre-configuring allowed commands and verifying user credentials in advance, the system maintains operational capability while preventing unauthorized access.
Solution Approach 2:
The patent employs feedback mechanisms where the system continuously monitors command execution on both paths and adjusts security policies based on detected patterns. This feedback loop enables the system to maintain high operational capability while dynamically responding to and preventing unauthorized access attempts.
3Reliability
If command states are locked for security, then security is improved, but command execution flexibility deteriorates
Solution Approach 1:
The patent implements dynamic command state management where command locks can be conditionally applied or released based on verified user credentials and security policies. This dynamic approach allows the system to maintain high security through selective locking while preserving command execution flexibility when proper authorization is provided.
Data Source
AI summary
Techniques are provided for protecting devices having multi-port hardware components. One method comprises obtaining a configuration of a command from a user to an enabled state or a disabled state on a port (e.g., an in-band port or an out-of-band port) of a hardware component of a processing device; automatically sharing credentials of the user with a basic input/output system of the processing device using a secure channel, in response to the obtained configuration; and initiating processing of a given command from a user, associated with a particular port of the hardware component, responsive to an evaluation of the shared user credentials and the given command being in the enabled state on the particular port. Changes with respect to a current enabled state or a current disabled state of a given command may be locked or unlocked.


