Validating Hardware Integrity in Shared Chassis IHS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face security risks due to the potential substitution of compromised hardware components during assembly or maintenance, which can compromise all systems sharing resources in a shared chassis, leading to vulnerabilities in processing and storage security.
Innovation Solution
A method for validating the secure assembly and delivery of IHSs installed in a shared chassis involves retrieving and comparing inventory certificates of factory-installed hardware components, using cryptographic keypairs to ensure the integrity of detected components, and sharing keypairs among IHSs to verify the authenticity of hardware components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of repair
If hardware components are replaced or new components are installed to an IHS, then maintenance and upgrades can be performed, but malicious actors can substitute compromised hardware components for genuine components
Solution Approach 1:
The system performs preliminary actions by creating cryptographic hashes of hardware component inventories during factory provisioning and storing them as inventory certificates. This preliminary hashing and certification establishes a baseline of authentic components before any replacement occurs, enabling later validation to detect substitutions.
Solution Approach 2:
The system implements feedback by continuously validating hardware component inventories against stored inventory certificates. The validation process compares current component hashes with certified hashes, providing feedback that detects any substitutions and triggers appropriate security responses.
2Adaptability or versatility
If multiple IHSs are installed in a single shared chassis, then resource sharing and system integration are improved, but a malicious actor can compromise all IHSs by targeting shared hardware components
Solution Approach 1:
The system applies segmentation by creating separate inventory certificates for each individual IHS while also creating a chassis-level inventory certificate for shared components. This segmentation allows validation of individual systems while maintaining awareness of shared resource security.
Solution Approach 2:
The system uses an intermediary approach by implementing a chassis management controller that coordinates validation across multiple IHSs. This intermediary manages the shared hardware inventory and facilitates cross-validation, detecting compromises that affect multiple systems.
3Reliability
If inventory certificates are validated using cryptographic keypairs, then hardware component integrity is ensured, but the complexity of the validation process increases
Solution Approach 1:
The system uses copying by creating cryptographic hashes (digital copies) of hardware inventory data and storing them as inventory certificates. These hash copies enable validation without requiring physical access to original components, simplifying the validation process while maintaining security.
Data Source
AI summary
Embodiments validate the secure assembly and delivery of IHSs (Information Handling Systems) that are installed in a shared chassis, such as two 1RU (rack unit) servers installed in a shared 2RU chassis. An inventory certificate is retrieved that was uploaded to a first IHS of the IHSs installed in the shared chassis during factory provisioning of the first IHS. The inventory certificate specifies factory installed hardware components installed in each of the IHSs of the shared chassis. A validation process of the first IHS collects an inventory of hardware components detected by each of the IHSs of the shared chassis. The validation process compares the collected inventory of detected hardware components of the IHSs against the factory installed hardware components specified in the inventory certificate in order to validate the detected hardware components as the same hardware components installed during factory assembly of each of the IHSs.


