Service Processor Local Key Management for Drive Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current local key management setups in information handling systems face issues such as easily detectable clear text user input passwords, absence of password recovery mechanisms, inability to unlock devices if the password management entity is unresponsive, and lack of password expiration management, which are not adequately addressed by existing solutions like distributed key management and Bitlocker.
Innovation Solution
A computer-implemented method and system for local key management that involves a service processor dynamically generating public-private keys and certificates, encrypting them, and archiving recovery keys and certificates in a database or server, allowing secure drive locking and unlocking, and enabling password recovery through a portable storage device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If clear text user input passwords are used for local key management, then ease of operation is improved, but security is worsened due to easily detectable passwords
Solution Approach 1:
The patent replaces the mechanical/manual password input system with an automated cryptographic key generation system. The service processor automatically generates cryptographic keys and manages authentication, eliminating the need for users to input passwords manually. This substitution resolves the contradiction by removing the weak link (clear text passwords) while maintaining ease of operation through automated authentication.
Solution Approach 2:
The patent introduces a service processor as an intermediary between the user and the storage devices. This intermediary automatically manages key generation, storage, and authentication processes, eliminating direct user interaction with passwords. The service processor acts as a mediator that handles security complexities while presenting a simple interface to users.
2Object-affected harmful factors
If no password recovery mechanism is implemented, then security is improved, but reliability is worsened due to inability to recover access
Solution Approach 1:
The patent segments the authentication system into multiple components: user credentials, service processor-stored keys, and recovery mechanisms. By dividing the authentication process into separate manageable parts, the system can implement recovery procedures without compromising overall security. The service processor maintains secure key storage while enabling authorized recovery through segmented authentication paths.
Solution Approach 2:
The patent implements preliminary recovery key generation and storage before authentication failures occur. The service processor pre-generates and securely stores recovery keys that can be used if primary authentication fails. This preliminary preparation ensures that recovery is possible without compromising security, as the recovery mechanism is established in advance through controlled procedures.
3Object-affected harmful factors
If the password management entity becomes unresponsive, then device security is maintained, but device unlocking capability is lost
Solution Approach 1:
The service processor acts as an intermediary that maintains authentication capabilities independently of external password management entities. By localizing key management functions within the service processor, the system can perform authentication and unlocking operations without requiring continuous communication with external password management systems, ensuring device accessibility even when external entities are unresponsive.
Solution Approach 2:
The service processor implements self-service authentication capabilities by maintaining local key storage and authentication logic. The system can independently verify credentials and unlock devices without requiring external password management entity intervention. This self-sufficiency ensures continuous device accessibility while maintaining security, as the service processor can handle authentication autonomously.
4Object-affected harmful factors
If distributed key management solution is implemented, then security and multi-user access are improved, but device complexity and cost increase
Solution Approach 1:
The patent merges key generation, storage, and authentication functions into a single integrated service processor unit. By combining these previously separate functions into one component, the system achieves distributed key management capabilities without the complexity of multiple separate systems. The service processor consolidates security management while maintaining the benefits of distributed architecture through centralized control within the processor.
Solution Approach 2:
The service processor is designed as a universal component that performs multiple functions: key generation, key storage, authentication, and device unlocking. This multi-functional design eliminates the need for separate dedicated components for each security function, reducing overall device complexity while maintaining comprehensive security capabilities. The universal service processor handles all security operations through integrated functionality.
Data Source
AI summary
A method and system for local key management setup and recovery includes receiving a lock request to secure one or more drives, then querying, for one or more key identifiers associated with a requesting device. The method includes: in response to receiving at least one key identifier, dynamically generating a first public-private key and a first public certificate associated with the at least one key identifier; and assigning the first public-private key and the first public certificate to the drives. The method further includes: concealing contents of the first public-private key and first public certificate; automatically transmitting the first public certificate to the first requesting device; and invoking the first public-private key to secure the drives. Finally, the method includes creating a recovery key, generating a recovery certificate associated with the recovery key, then, archiving the recovery key and the recovery certificate in a recovery database and a recovery server.


