Multi-Port Hardware Component Protection via Secure Credential Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware devices with both in-band and out-of-band management capabilities are vulnerable to malicious exploitation, as existing security measures fail to effectively control and manage privileged commands on these paths, leading to potential unauthorized access and malicious acts.

Innovation Solution

A method that configures user commands on multiple ports of a processing device to enabled or disabled states, sharing credentials securely through a basic input/output system to control and manage in-band and out-of-band paths, ensuring that only authorized commands are executed and preventing unauthorized access by locking or unlocking command states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If in-band and out-of-band management capabilities are enabled for hardware devices, then management flexibility and control are improved, but security vulnerabilities increase due to potential malicious exploitation

Engineering Contradiction:
Improvemanagement flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the management paths into in-band and out-of-band channels, applying distinct security policies and credential verification mechanisms to each path. This segmentation allows the system to maintain management flexibility while addressing security vulnerabilities through path-specific controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential sharing mechanism between the in-band and out-of-band management paths. This intermediary system verifies credentials and enforces security policies, allowing both management paths to function while preventing malicious exploitation through centralized security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If privileged commands are allowed on both in-band and out-of-band paths, then operational capability is improved, but unauthorized access risk increases

Engineering Contradiction:
Improveoperational capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary credential verification and command authorization before executing privileged commands on either in-band or out-of-band paths. By pre-configuring allowed commands and verifying user credentials in advance, the system maintains operational capability while preventing unauthorized access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms where the system continuously monitors command execution on both paths and adjusts security policies based on detected patterns. This feedback loop enables the system to maintain high operational capability while dynamically responding to and preventing unauthorized access attempts.

Inventive Principle:
Principle #23Feedback

3Reliability

If command states are locked for security, then security is improved, but command execution flexibility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommand execution flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic command state management where command locks can be conditionally applied or released based on verified user credentials and security policies. This dynamic approach allows the system to maintain high security through selective locking while preserving command execution flexibility when proper authorization is provided.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240143850A1Protection of processing devices having multi-port hardware components
Publication Date: 2024.05.02 DELL PROD LP
  • US20240143850A1 patent drawing
  • US20240143850A1 patent drawing
  • US20240143850A1 patent drawing

AI summary

Techniques are provided for protecting devices having multi-port hardware components. One method comprises obtaining a configuration of a command from a user to an enabled state or a disabled state on a port (e.g., an in-band port or an out-of-band port) of a hardware component of a processing device; automatically sharing credentials of the user with a basic input/output system of the processing device using a secure channel, in response to the obtained configuration; and initiating processing of a given command from a user, associated with a particular port of the hardware component, responsive to an evaluation of the shared user credentials and the given command being in the enabled state on the particular port. Changes with respect to a current enabled state or a current disabled state of a given command may be locked or unlocked.