Resource/control plane/LCS authentication system
A resource/control plane/LCS authentication system includes a resource system coupled to a resource management system. The resource system includes an SCP device that authenticates with the resource management system to provide an authenticated LCS control plane. An operating system in the resource system signs operating system authentication information and transmits the signed operating system authentication information to the resource management system to provide an authenticated resource system. The operating system creates an LCS vTPM for an LCS that was composed by the resource management system, and stores an LCS vTPM payload from the resource management system in the LCS vTPM. The operating system then provides the LCS using the LCS vTPM payload, with the LCS authenticating itself and the operating system to provide an authenticated LCS. The operating system then performs a workload using the authenticated LCS, the authenticated resource system, and the authenticated LCS control plane.
1 . A resource/control plane/Logically Composed System (LCS) authentication system, comprising:
a resource management system; and
a resource system that is coupled to the resource management system and that includes:
a System Control Processor (SCP) device that includes at least one SCP hardware processing system that is configured to execute instructions stored on at least one SCP memory system to authenticate with the resource management system to provide an authenticated Logically Composed System (LCS) control plane;
a Basic Input/Output System (BIOS) that includes at least one BIOS hardware processing system that is configured to execute instructions stored on at least one BIOS memory system to provide BIOS operating system authentication information in an authentication information database with resource management operating system authentication information provided by the resource management system; and
an operating system that includes at least one operating system hardware processing system that is configured to execute instructions stored on at least one operating system memory system to:
sign the BIOS operating system authentication information and the resource management operating system authentication information to provide signed operating system authentication information;
transmit the signed operating system authentication information to the resource management system to provide an authenticated resource system;
create an LCS virtual Trusted Platform Module (vTPM) for an LCS that was composed by the resource management system;
receive an LCS vTPM payload for the LCS from the resource management system and store the LCS vTPM payload in the LCS vTPM;
provide the LCS using the LCS vTPM payload, wherein the LCS includes at least one LCS hardware processing system that is configured to execute instructions stored on at least one LCS memory system to authenticate itself and the operating system to provide an authenticated LCS; and
perform a workload using the authenticated LCS, the authenticated resource system, and the authenticated LCS control plane.
2 . The system of claim 1 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
authenticate with the resource management system using an operating system identity certificate for a current instance of the operating system being provided on the resource system during a current power cycle.
3 . The system of claim 1 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
generate LCS vTPM access information for the LCS vTPM; and
store the LCS vTPM access information in a Trusted Platform Module (TPM) device that is included in the resource system.
4 . The system of claim 3 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
sign the LCS vTPM access information to generate signed LCS vTPM access information;
transmit the signed LCS vTPM access information to the resource management system;
receive an encrypted LCS vTPM payload for the LCS that is provided by the LCS vTPM payload encrypted with the signed LCS vTPM access information;
decrypt the encrypted LCS vTPM payload to provide the LCS vTPM payload; and
store the LCS vTPM payload in the LCS vTPM.
5 . The system of claim 1 , wherein operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
receive, from the LCS, an LCS vTPM write request for the vTPM and, in response, provide write information in the LCS vTPM.
6 . The system of claim 5 , wherein operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
synchronize, with the resource management system, the write information provided in the LCS vTPM.
7 . An Information Handling System (IHS), comprising:
a System Control Processor (SCP) device that includes at least one SCP hardware processing system that is configured system that is configured to execute instructions stored on at least one SCP memory system to authenticate with a resource management system to provide an authenticated Logically Composed System (LCS) control plane;
a Basic Input/Output System (BIOS) that includes at least one BIOS hardware processing system that is configured to execute instructions stored on at least one BIOS memory system to provide BIOS operating system authentication information in an authentication information database with resource management operating system authentication information provided by the resource management system; and
an operating system that includes at least one operating system hardware processing system that is configured to execute instructions stored on at least one operating system memory system to:
sign the BIOS operating system authentication information and the resource management operating system authentication information to provide signed operating system authentication information;
transmit the signed operating system authentication information to the resource management system to provide an authenticated resource system;
create an LCS virtual Trusted Platform Module (vTPM) for an LCS that was composed by the resource management system;
receive an LCS vTPM payload for the LCS from the resource management system and store the LCS vTPM payload in the LCS vTPM;
provide the LCS using the LCS vTPM payload, wherein the LCS includes at least one LCS hardware processing system that is configured to execute instructions stored on at least one LCS memory system to authenticate itself and the operating system to provide an authenticated LCS; and
perform a workload using the authenticated LCS, the authenticated resource system, and the authenticated LCS control plane.
8 . The IHS of claim 7 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
authenticate with the resource management system using an operating system identity certificate for a current instance of the operating system being provided on the resource system during a current power cycle.
9 . The IHS of claim 7 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
generate LCS vTPM access information for the LCS vTPM; and
store the LCS vTPM access information in a Trusted Platform Module (TPM) device that is included in the resource system.
10 . The IHS of claim 9 , wherein the operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
sign the LCS vTPM access information to generate signed LCS vTPM access information;
transmit the signed LCS vTPM access information to the resource management system;
receive an encrypted LCS vTPM payload for the LCS that is provided by the LCS vTPM payload encrypted with the signed LCS vTPM access information;
decrypt the encrypted LCS vTPM payload to provide the LCS vTPM payload; and
store the LCS vTPM payload in the LCS vTPM.
11 . The IHS of claim 7 , wherein operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
receive, from the LCS, an LCS vTPM read request for the vTPM and, in response, retrieve read information from the LCS vTPM and provide the read information to the LCS.
12 . The IHS of claim 7 , wherein operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
receive, from the LCS, an LCS vTPM write request for the vTPM and, in response, provide write information in the LCS vTPM.
13 . The IHS of claim 12 , wherein operating system includes the at least one operating system hardware processing system that is configured to execute the instructions stored on the at least one operating system memory system to:
synchronize, with the resource management system, the write information provided in the LCS vTPM.
14 . A method for authenticating a Logically Composed System (LCS) along with the resource system and the LCS control plane that are used to provide that LCS, comprising:
authenticating, by a System Control Processor (SCP) device that is included in a resource system using at least one SCP processing system executing instructions stored on at least one SCP memory system, with a resource management system to provide an authenticated Logically Composed System (LCS) control plane;
providing, by a Basic Input/Output System (BIOS) that is included in the resource system using at least one BIOS processing system executing instructions stored on at least one BIOS memory system, BIOS operating system authentication information in an authentication information database with resource management operating system authentication information provided by the resource management system;
signing, by an operating system that is provided by the resource system using at least one operating system processing system executing instructions stored on at least one operating system memory system, the BIOS operating system authentication information and the resource management operating system authentication information to provide signed operating system authentication information;
transmitting, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the signed operating system authentication information to the resource management system to provide an authenticated resource system;
creating, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, an LCS virtual Trusted Platform Module (vTPM) for an LCS that was composed by the resource management system;
receiving, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, an LCS vTPM payload for the LCS from the resource management system and store the LCS vTPM payload in the LCS vTPM;
providing, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the LCS using the LCS vTPM payload, wherein the LCS includes at least one LCS hardware processing system that is configured to execute instructions stored on at least one LCS memory system to authenticate itself and the operating system to provide an authenticated LCS; and
performing, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, a workload using the authenticated LCS, the authenticated resource system, and the authenticated LCS control plane.
15 . The method of claim 14 , further comprising:
authenticating, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, with the resource management system using an operating system identity certificate for a current instance of the operating system being provided on the resource system during a current power cycle.
16 . The method of claim 14 , further comprising:
generating, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, LCS vTPM access information for the LCS vTPM; and
storing, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the LCS vTPM access information in a Trusted Platform Module (TPM) device that is included in the resource system.
17 . The method of claim 14 , further comprising:
signing, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the LCS vTPM access information to generate signed LCS vTPM access information;
transmitting, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the signed LCS vTPM access information to the resource management system;
receiving, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, an encrypted LCS vTPM payload for the LCS that is provided by the LCS vTPM payload encrypted with the signed LCS vTPM access information;
decrypting, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the encrypted LCS vTPM payload to provide the LCS vTPM payload; and
storing, by the operating system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the LCS vTPM payload in the LCS vTPM.
18 . The method of claim 14 , further comprising:
receiving, by the operating system from the LCS using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, an LCS vTPM read request for the vTPM and, in response, retrieving read information from the LCS vTPM and providing the read information to the LCS.
19 . The method of claim 14 , further comprising:
receiving, by the operating system from the LCS using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, an LCS vTPM write request for the vTPM and, in response, providing write information in the LCS vTPM.
20 . The method of claim 14 , further comprising:
synchronizing, by the operating system with the resource management system using the at least one operating system processing system executing the instructions stored on the at least one operating system memory system, the write information provided in the LCS vTPM.