Server Node Authentication via Hardware Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The merging of multiple server nodes in enterprise environments is vulnerable to security threats due to the lack of trusted authentication protocols, particularly when service processors are untrusted, leading to risks of spoofing, tampering, and other attacks.

Innovation Solution

Implementing an authentication protocol that uses provisioned node certificates and establishes a hardware secure channel between server nodes to exchange a shared secret, confirm security configurations, and manage TPM logs, allowing for concurrent node addition and removal without requiring a system initial program load (IPL).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service processor controls node merge operation, then node merging capability is improved, but security vulnerability increases due to untrusted service processor

Engineering Contradiction:
Improvenode merging capabilityVSAvoidsecurity trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a hardware secure channel as an intermediary between server nodes for authentication purposes. This secure channel acts as a trusted mediator that allows nodes to exchange authentication information securely, even when the service processor controlling the merge operation is untrusted. The hardware secure channel isolates the critical authentication path from the untrusted service processor, resolving the contradiction between node merging capability and security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process from the service processor control plane by establishing direct hardware secure channels between nodes. This segmentation separates the trusted authentication path (direct node-to-node communication) from the untrusted management path (service processor control), allowing node merging functionality while protecting security through architectural separation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication protocol is implemented for secure node merging, then security is improved, but system complexity increases due to additional authentication mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication protocol is designed to be self-service in that server nodes autonomously perform mutual authentication through hardware secure channels without requiring complex external authentication infrastructure. Each node independently verifies the other's identity using TPM-based credentials, eliminating the need for complex centralized authentication management and reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If concurrent node add and remove is supported, then system adaptability is improved, but authentication validation complexity increases

Engineering Contradiction:
Improvedynamic node changesVSAvoidauthentication validation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication protocol is designed to be dynamic, allowing nodes to be added or removed from the cluster concurrently without requiring system shutdown or re-initialization. The hardware secure channels and TPM-based authentication enable real-time validation of node identities during dynamic configuration changes, maintaining security while supporting flexible system adaptation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11165766B2Implementing authentication protocol for merging multiple server nodes with trusted platform modules utilizing provisioned node certificates to support concurrent node add and remove
Publication Date: 2021.11.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11165766B2 patent drawing
  • US11165766B2 patent drawing
  • US11165766B2 patent drawing

AI summary

A method and computer system for implementing authentication protocol for merging multiple server nodes with trusted platform modules (TPMs) utilizing provisioned node certificates to support concurrent node add and node remove. Each of the multiple server nodes boots an instance of enablement level firmware and extended to a trusted platform module (TPM) on each node as the server nodes are powered up. A hardware secure channel is established between the server nodes for firmware message passing as part of physical configuration of the server nodes to be merged. A shared secret is securely exchanged via the hardware secure channel between the server nodes establishing an initial authentication value shared among all server nodes. All server nodes confirm common security configuration settings and exchange TPM log and platform configuration register (PCR) data to establish common history for future attestation requirements, enabling dynamic changing the server nodes and concurrently adding and removing nodes.