Server Fabric Security Zones for Data Center Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data center security systems lack effective integration of server systems on a chip (SoCs) and server fabrics, which are essential for enhancing network security and protecting against malicious activities.

Innovation Solution

The implementation of a data center security system that leverages server systems on a chip (SoCs) and server fabrics, utilizing a management processor running in the Secure world to provide out-of-band security, isolate compromised nodes, and offer secure communication and logging paths, along with dynamic security zone management and secure boot-loading, to enhance security and integrity monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security appliances (IDS/IPS) are implemented out-of-line or in-line, then intrusion detection and prevention capabilities are provided, but the system complexity increases and performance degradation occurs

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines intrusion detection, intrusion prevention, and security management functions directly into the server fabric and SoC infrastructure. The fabric itself becomes the security enforcement point, merging multiple security functions into the core networking infrastructure rather than adding separate appliances.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server fabric is designed to perform both networking functions and security functions simultaneously. The same fabric infrastructure that routes traffic also performs intrusion detection, prevention, and policy enforcement, making the system multi-functional and eliminating the need for separate security appliances.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security zones are implemented in SoC to partition hardware and software resources, then security perimeter is strengthened, but device complexity increases

Engineering Contradiction:
Improvesecurity perimeterVSAvoidSoC complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SoC is divided into distinct security zones that partition hardware and software resources. Each zone has defined security boundaries and access controls, creating a segmented architecture where compromise in one zone does not necessarily affect other zones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security policies and protection levels are applied to different zones within the SoC. Each zone can have customized security characteristics appropriate to its function, allowing localized security optimization without uniformly increasing complexity across the entire system.

Inventive Principle:
Principle #3Local quality

3Reliability

If management processor communication is secured through out-of-band paths, then communication integrity is maintained, but system complexity increases

Engineering Contradiction:
Improvecommunication integrityVSAvoidcommunication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A dedicated management processor communicates through secured out-of-band paths that are separate from the main data plane. This intermediary communication channel provides integrity protection for management traffic without interfering with normal data flow, using the fabric's built-in security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9929976B2System and method for data center security enhancements leveraging managed server SOCs
Publication Date: 2018.03.27 III HOLDINGS 2 LLC
  • US9929976B2 patent drawing
  • US9929976B2 patent drawing
  • US9929976B2 patent drawing

AI summary

A data center security system and method are provided that leverage server systems on a chip (SOCs) and/or server fabrics. In more detail, server interconnect fabrics may be leveraged and extended to dramatically improve security within a data center.