SmartNIC Authentication via External Token Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to server management using a smart network interface card (smartNIC) face security concerns due to the need to store usernames and passwords for management controllers on the smartNIC.

Innovation Solution

The proposed solution involves an information handling system that includes a processor, a management controller for out-of-band management, and a smartNIC. The smartNIC obtains a secret for authentication, requests an access token reference from the management controller, receives the access token reference, and uses it to communicate management task requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the smartNIC stores username and password for the management controller, then the smartNIC can authenticate to the management controller, but security concerns arise

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive credentials (username and password) from the smartNIC and stores them externally in a secure element or hardware security module. The smartNIC only retains a reference or token to access these credentials when needed, eliminating the security risk of storing passwords locally while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary component (such as a secure element, hardware security module, or external authentication service) that acts as a mediator between the smartNIC and the management controller. This intermediary securely stores the credentials and provides authentication information to the smartNIC without requiring the smartNIC to store the actual password, thus resolving the security contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If the smartNIC performs power operations and system management operations independently, then the smartNIC can react to failures when virtual machine manager is unavailable, but the need for stored credentials creates security vulnerabilities

Engineering Contradiction:
Improveindependent management capabilityVSAvoidsecurity risk
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts credential storage from the smartNIC's local memory and places it in an external secure storage mechanism. This allows the smartNIC to independently perform management operations while obtaining authentication credentials on-demand from the external secure storage, eliminating the security vulnerability of local credential storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the smartNIC communicates with an external secure element or hardware security module to obtain authentication tokens. This intermediary approach enables independent operation while maintaining security by not requiring the smartNIC to store sensitive credentials locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12222882B2Systems and methods for smart network interface card-initiated server management
Publication Date: 2025.02.11 DELL PROD LP
  • US12222882B2 patent drawing
  • US12222882B2 patent drawing

AI summary

An information handling system may include a processor, a management controller communicatively coupled to the processor and configured for out-of-band management of the information handling system, and a smart network interface card communicatively coupled to the processor and the management controller, and configured to obtain a secret for authenticating the smart network interface card to the management controller, request an access token reference from the management controller, the request including the secret and an identifier of the smart network interface card in order to authenticate the smart network interface card to the management controller, in response to the request for the access token reference, receive the access token reference, and communicate a management task request to the management controller using the access token reference.