Non-Volatile Memory Region Configuration for Secure Network Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network boot environments face challenges in configuring non-volatile memory, particularly with three-dimensional cross-point devices that combine RAM, FLASH, and mass-storage characteristics, as current provisioning methods like PXE do not function properly with these devices, requiring partitioning and configuration before they can hold images and containers securely.
Innovation Solution
A management controller enables configuration of non-volatile memory into regions for use as non-persistent primary RAM, secondary RAM, non-volatile block storage, and persistent RAM, using configuration information to set sizes and address ranges, and incorporates security features like signature verification and encryption to securely deploy operating systems and workload containers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional storage (ROM, FLASH, magnetic disk) is used for network boot environments, then compatibility with existing PXE provisioning mechanisms is maintained, but the ability to securely hold operating system images and containers is limited
Solution Approach 1:
The non-volatile memory is divided into multiple distinct regions: a first region for storing PXE boot code and configuration data, and a second region for securely storing operating system images and containers. This segmentation allows each region to be optimized for its specific purpose while maintaining overall system compatibility and security
Solution Approach 2:
Different portions of the non-volatile memory are assigned different functional characteristics - the first region is configured for boot operations with appropriate read-execute permissions, while the second region is configured for secure storage with encryption capabilities and restricted access controls
2Reliability
If non-volatile memory is partitioned into multiple regions for different functions, then secure storage of OS images and containers is enabled, but the complexity of memory configuration increases
Solution Approach 1:
The memory partitioning scheme, region boundaries, and access control policies are pre-configured during system initialization or manufacturing. This preliminary configuration establishes the security framework before any operating system images or containers are deployed, simplifying subsequent operations
Solution Approach 2:
A memory management layer or controller acts as an intermediary between the hardware non-volatile memory and the software components. This intermediary handles the complexity of region management, access control, and encryption transparently, allowing higher-level systems to use the storage without directly managing the partitioning complexity
3Productivity
If non-volatile memory is used to hold operating system images and containers, then provisioning efficiency is improved, but unauthorized access and security risks increase
Solution Approach 1:
Security measures are implemented in advance before any unauthorized access can occur. Encryption keys are generated and stored securely, access control lists are configured, and authentication mechanisms are established during system setup. This preliminary security framework prevents unauthorized access before it can compromise the provisioning efficiency
Solution Approach 2:
The security model combines multiple protective layers: encryption algorithms, access control mechanisms, authentication protocols, and secure key management. These composite security measures work together to protect the non-volatile memory contents while allowing legitimate provisioning operations to proceed efficiently
Data Source
AI summary
Various embodiments are generally directed to an apparatus, method and other techniques to store a first set of instructions in a first portion of the non-volatile memory, the first set of instructions to configure a second portion of the non-volatile memory, cause the processing unit to process the first set of instructions to configure the second portion with one or more regions, and cause a configuration of the memory controller based on the first set of instructions.


