SmartNIC Authentication via External Token Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches to server management using a smart network interface card (smartNIC) face security concerns due to the need to store usernames and passwords for management controllers on the smartNIC.
Innovation Solution
The proposed solution involves an information handling system that includes a processor, a management controller for out-of-band management, and a smartNIC. The smartNIC obtains a secret for authentication, requests an access token reference from the management controller, receives the access token reference, and uses it to communicate management task requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the smartNIC stores username and password for the management controller, then the smartNIC can authenticate to the management controller, but security concerns arise
Solution Approach 1:
The patent extracts the sensitive credentials (username and password) from the smartNIC and stores them externally in a secure element or hardware security module. The smartNIC only retains a reference or token to access these credentials when needed, eliminating the security risk of storing passwords locally while maintaining authentication capability.
Solution Approach 2:
The patent introduces an intermediary component (such as a secure element, hardware security module, or external authentication service) that acts as a mediator between the smartNIC and the management controller. This intermediary securely stores the credentials and provides authentication information to the smartNIC without requiring the smartNIC to store the actual password, thus resolving the security contradiction.
2Extent of automation
If the smartNIC performs power operations and system management operations independently, then the smartNIC can react to failures when virtual machine manager is unavailable, but the need for stored credentials creates security vulnerabilities
Solution Approach 1:
The patent extracts credential storage from the smartNIC's local memory and places it in an external secure storage mechanism. This allows the smartNIC to independently perform management operations while obtaining authentication credentials on-demand from the external secure storage, eliminating the security vulnerability of local credential storage.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the smartNIC communicates with an external secure element or hardware security module to obtain authentication tokens. This intermediary approach enables independent operation while maintaining security by not requiring the smartNIC to store sensitive credentials locally.
Data Source
AI summary
An information handling system may include a processor, a management controller communicatively coupled to the processor and configured for out-of-band management of the information handling system, and a smart network interface card communicatively coupled to the processor and the management controller, and configured to obtain a secret for authenticating the smart network interface card to the management controller, request an access token reference from the management controller, the request including the secret and an identifier of the smart network interface card in order to authenticate the smart network interface card to the management controller, in response to the request for the access token reference, receive the access token reference, and communicate a management task request to the management controller using the access token reference.

