Secure BMC Initialization via Encrypted Interconnect Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Converged infrastructure setups for rack servers face challenges in secure, automated initialization of Baseboard Management Controllers (BMCs) due to vulnerabilities in out-of-band management processes, making them susceptible to unauthorized access and denial-of-service attacks.

Innovation Solution

An automated and end-to-end encrypted and authenticated channel is established from manageability applications to network interconnect devices to securely initiate login with newly connected servers, using a first secure connection to communicate login information and subsequently changing it to new information for subsequent use, ensuring secure Out of Band (OOB) deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual or scripted methods are used to initialize BMCs, then setup flexibility is maintained, but security vulnerabilities increase due to exposure of default credentials

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically generating unique credentials before the BMC initialization process and injecting them into the BMC during out-of-band execution. This preliminary credential generation and injection eliminates the need for manual credential configuration and prevents exposure of default credentials, thereby improving security while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated out-of-band management processes are implemented, then setup efficiency improves, but security vulnerabilities increase due to potential misuse by hackers

Engineering Contradiction:
Improvesetup efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces an intermediary credential management mechanism that acts as a secure bridge between the automated management process and the BMC. Unique credentials are generated and injected through this intermediary layer during out-of-band execution, preventing direct exposure of credentials and blocking hacker access paths while maintaining automated setup efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If default BMC credentials are used, then initialization is simplified, but the system becomes susceptible to unauthorized access and attacks

Engineering Contradiction:
Improveinitialization simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system extracts the credential generation and injection process from the standard initialization flow and implements it as a separate secure out-of-band operation. By taking out the credential management function and executing it through a dedicated secure channel, the system maintains initialization simplicity while eliminating the security risk associated with exposed default credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If secure credential injection is implemented during out-of-band execution, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling the BMC to automatically receive and configure unique credentials through out-of-band execution without requiring manual intervention or complex external credential management infrastructure. The BMC serves itself by processing the injected credentials autonomously, which improves security while avoiding the complexity of additional credential management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10749858B2Secure login information
Publication Date: 2020.08.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10749858B2 patent drawing
  • US10749858B2 patent drawing
  • US10749858B2 patent drawing

AI summary

An example device includes a processor coupled to a network and a memory coupled to the processor. The memory includes computer code for causing the processor to establish a secure connection between a manageability application and an interconnect device, the interconnect device being in communication with a newly connected networked device; and securely communicate, from the manageability application to the interconnect device, temporary login information for the networked device.