Validating Hardware Integrity in Shared Chassis IHS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face security risks due to the potential substitution of compromised hardware components during assembly or maintenance, which can compromise all systems sharing resources in a shared chassis, leading to vulnerabilities in processing and storage security.

Innovation Solution

A method for validating the secure assembly and delivery of IHSs installed in a shared chassis involves retrieving and comparing inventory certificates of factory-installed hardware components, using cryptographic keypairs to ensure the integrity of detected components, and sharing keypairs among IHSs to verify the authenticity of hardware components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If hardware components are replaced or new components are installed to an IHS, then maintenance and upgrades can be performed, but malicious actors can substitute compromised hardware components for genuine components

Engineering Contradiction:
Improvehardware component replacementVSAvoidhardware component authenticity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The system performs preliminary actions by creating cryptographic hashes of hardware component inventories during factory provisioning and storing them as inventory certificates. This preliminary hashing and certification establishes a baseline of authentic components before any replacement occurs, enabling later validation to detect substitutions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously validating hardware component inventories against stored inventory certificates. The validation process compares current component hashes with certified hashes, providing feedback that detects any substitutions and triggers appropriate security responses.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple IHSs are installed in a single shared chassis, then resource sharing and system integration are improved, but a malicious actor can compromise all IHSs by targeting shared hardware components

Engineering Contradiction:
Improveresource sharing capabilityVSAvoidsecurity vulnerability propagation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies segmentation by creating separate inventory certificates for each individual IHS while also creating a chassis-level inventory certificate for shared components. This segmentation allows validation of individual systems while maintaining awareness of shared resource security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses an intermediary approach by implementing a chassis management controller that coordinates validation across multiple IHSs. This intermediary manages the shared hardware inventory and facilitates cross-validation, detecting compromises that affect multiple systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If inventory certificates are validated using cryptographic keypairs, then hardware component integrity is ensured, but the complexity of the validation process increases

Engineering Contradiction:
Improvehardware validation securityVSAvoidvalidation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses copying by creating cryptographic hashes (digital copies) of hardware inventory data and storing them as inventory certificates. These hash copies enable validation without requiring physical access to original components, simplifying the validation process while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11514193B2Validating secure assembly and delivery of multiple information handling systems installed in a shared chassis
Publication Date: 2022.11.29 DELL PROD LP
  • US11514193B2 patent drawing
  • US11514193B2 patent drawing
  • US11514193B2 patent drawing

AI summary

Embodiments validate the secure assembly and delivery of IHSs (Information Handling Systems) that are installed in a shared chassis, such as two 1RU (rack unit) servers installed in a shared 2RU chassis. An inventory certificate is retrieved that was uploaded to a first IHS of the IHSs installed in the shared chassis during factory provisioning of the first IHS. The inventory certificate specifies factory installed hardware components installed in each of the IHSs of the shared chassis. A validation process of the first IHS collects an inventory of hardware components detected by each of the IHSs of the shared chassis. The validation process compares the collected inventory of detected hardware components of the IHSs against the factory installed hardware components specified in the inventory certificate in order to validate the detected hardware components as the same hardware components installed during factory assembly of each of the IHSs.