Non-Volatile Memory Region Configuration for Secure Network Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network boot environments face challenges in configuring non-volatile memory, particularly with three-dimensional cross-point devices that combine RAM, FLASH, and mass-storage characteristics, as current provisioning methods like PXE do not function properly with these devices, requiring partitioning and configuration before they can hold images and containers securely.

Innovation Solution

A management controller enables configuration of non-volatile memory into regions for use as non-persistent primary RAM, secondary RAM, non-volatile block storage, and persistent RAM, using configuration information to set sizes and address ranges, and incorporates security features like signature verification and encryption to securely deploy operating systems and workload containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional storage (ROM, FLASH, magnetic disk) is used for network boot environments, then compatibility with existing PXE provisioning mechanisms is maintained, but the ability to securely hold operating system images and containers is limited

Engineering Contradiction:
Improvesecurity of OS image storageVSAvoidcompatibility with PXE provisioning
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The non-volatile memory is divided into multiple distinct regions: a first region for storing PXE boot code and configuration data, and a second region for securely storing operating system images and containers. This segmentation allows each region to be optimized for its specific purpose while maintaining overall system compatibility and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the non-volatile memory are assigned different functional characteristics - the first region is configured for boot operations with appropriate read-execute permissions, while the second region is configured for secure storage with encryption capabilities and restricted access controls

Inventive Principle:
Principle #3Local quality

2Reliability

If non-volatile memory is partitioned into multiple regions for different functions, then secure storage of OS images and containers is enabled, but the complexity of memory configuration increases

Engineering Contradiction:
Improvesecure storage capabilityVSAvoidmemory configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The memory partitioning scheme, region boundaries, and access control policies are pre-configured during system initialization or manufacturing. This preliminary configuration establishes the security framework before any operating system images or containers are deployed, simplifying subsequent operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A memory management layer or controller acts as an intermediary between the hardware non-volatile memory and the software components. This intermediary handles the complexity of region management, access control, and encryption transparently, allowing higher-level systems to use the storage without directly managing the partitioning complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If non-volatile memory is used to hold operating system images and containers, then provisioning efficiency is improved, but unauthorized access and security risks increase

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Security measures are implemented in advance before any unauthorized access can occur. Encryption keys are generated and stored securely, access control lists are configured, and authentication mechanisms are established during system setup. This preliminary security framework prevents unauthorized access before it can compromise the provisioning efficiency

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The security model combines multiple protective layers: encryption algorithms, access control mechanisms, authentication protocols, and secure key management. These composite security measures work together to protect the non-volatile memory contents while allowing legitimate provisioning operations to proceed efficiently

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS10042651B2Techniques to configure multi-mode storage devices in remote provisioning environments
Publication Date: 2018.08.07 INTEL CORP
  • US10042651B2 patent drawing
  • US10042651B2 patent drawing
  • US10042651B2 patent drawing

AI summary

Various embodiments are generally directed to an apparatus, method and other techniques to store a first set of instructions in a first portion of the non-volatile memory, the first set of instructions to configure a second portion of the non-volatile memory, cause the processing unit to process the first set of instructions to configure the second portion with one or more regions, and cause a configuration of the memory controller based on the first set of instructions.