Virtual Private ChMCs for Multi-Tenant Server Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant chassis environments, managing shared resources and blade servers efficiently while maintaining security and scalability is challenging, particularly in ensuring each tenant has isolated and secure access to their allocated resources for monitoring and management.
Innovation Solution
Implementing virtual private chassis management controllers (CMCs) and virtual baseboard management controllers (BMCs) that partition the management network to create secure, private channels for each tenant, allowing them to monitor and manage their allocated resources independently, while a centralized CMC manages common functions across all tenants.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized management controller is used to manage all tenants, then device complexity is reduced and ease of operation is improved, but security and isolation between tenants deteriorate
Solution Approach 1:
The patent divides the centralized management controller into multiple virtual private CMC instances, each dedicated to a specific tenant. This segmentation allows the system to maintain the operational simplicity of centralized management while providing the security and isolation of dedicated controllers. Each virtual CMC instance manages only its assigned tenant's resources, preventing unauthorized access between tenants while presenting a unified management interface.
Solution Approach 2:
The patent introduces a virtualization layer that acts as an intermediary between the physical CMC hardware and multiple tenants. This virtualization layer creates virtual private CMC instances that mediate all management operations, providing tenant isolation through virtual boundaries while maintaining a single point of access for administrators. The intermediary layer ensures that each tenant interacts only with their allocated resources through their dedicated virtual CMC instance.
2Reliability
If separate management controllers are provided for each tenant, then security and isolation are improved, but device complexity and cost increase
Solution Approach 1:
The patent merges multiple virtual private CMC instances into a single physical CMC device. Instead of requiring separate physical controllers for each tenant, the system combines them in one unified hardware platform with virtualization capabilities. This merging reduces device complexity and cost while maintaining the security benefits of isolated management instances through virtual boundaries.
Solution Approach 2:
The patent makes the CMC device universal by enabling it to serve multiple tenants simultaneously through virtualization. A single CMC device performs the functions of multiple dedicated controllers by creating isolated virtual instances, each tailored to a specific tenant's requirements. This multi-functionality allows one device to replace many while maintaining the same level of security and isolation.
3Adaptability or versatility
If virtual private CMC instances are implemented for each tenant, then security and scalability are improved, but manufacturing complexity and initial setup complexity increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring the CMC device with virtualization capabilities and tenant profiles during manufacturing or initial deployment. The system is prepared in advance to automatically create and manage virtual private CMC instances as tenants are added. This preliminary setup reduces the complexity of subsequent tenant onboarding and scaling operations.
Solution Approach 2:
The patent enables self-service by allowing the virtual CMC instances to be automatically created, configured, and managed through software rather than requiring complex manual hardware configuration for each tenant. The system automatically handles the provisioning of virtual instances, network isolation, and resource allocation, significantly reducing deployment complexity while maintaining scalability.
Data Source
AI summary
An information handling system includes a chassis management controller (CMC) with a service processor, a processing system including a baseboard management controller (BMC) with a service processor, and a chassis management network coupled to the CMC and the BMC. The CMC instantiates a virtual CMC and the BMC instantiates a virtual BMC client. The virtual CMC is coupled to the virtual BMC client by a virtual management network of the chassis management network. The CMC is operable to manage the processing system via the BMC and the virtual CMC is operable to manage the processing system via the virtual BMC client.


