IP Library Granted Patent US 8,677,459
Granted Patent B2
US 8,677,459 · App. 12/551,068 · Granted Mar 18, 2014

Secure zero-touch provisioning of remote management controller

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,677,459
App. No.
12/551,068
Granted
Mar 18, 2014
Kind
B2
Abstract

Embodiments enable secure zero-touch remote provisioning/management of a computer system. A computer system is shipped to end customers with its remote management controller enabled but not provisioned. During automatic testing, for example, provisioning authentication data is embedded into the remote management controller. The computer system vendor harvests the provisioning authentication data or derivative data therefrom from the remote management controller and stores it in a database. Upon sale of the computer system, the computer system vendor provides to the end-customer the harvested data of the computer system's remote management controller. The end-customer can then remotely authenticate a remote provisioning/management console to the remote management controller. Once successfully authenticated, the remote provisioning/management console can provision the remote management controller with one or more user accounts/roles with corresponding authentication details, authenticate as one of the provisioned user accounts, and perform computer system provisioning using remote manageability functions as desired.

Claims (47)

1. A remote management controller, comprising:

one-time-programmable (OTP) memory that stores provisioning authentication data associated with the remote management controller; and

random access memory (RAM) that stores program logic associated with the remote management controller, wherein the program logic authenticates a remote provisioning console using the provisioning authentication data before allowing said remote provisioning console to provision the remote management controller,

wherein the provisioning authentication data includes a device key associated with the remote management controller and a provision mode value representative of a provisioning mode of the remote management controller.

2. The remote management controller of claim 1 , wherein the OTP memory stores a duplicate copy of the device key.

3. The remote management controller of claim 1 , wherein the device key is pseudo-randomly generated and programmed in the OTP memory during electrical testing of the remote management controller.

4. The remote management controller of claim 1 , wherein the provision mode value indicates whether the remote management controller is currently provisioned or unprovisioned and a number of times that the remote management controller has been provisioned.

5. The remote management controller of claim 1 , wherein the program logic authenticates the remote provisioning console by comparing login credentials provided by the remote provisioning console with provisioning login credentials associated with the remote management controller, the provisioning login credentials including a username and a password derived from the device key and the provision mode value of the remote management controller.

6. The remote management controller of claim 5 , wherein the program logic changes the provision mode value after the remote provisioning console provisions the remote management controller, to transition the remote management controller to a provisioned mode.

7. The remote management controller of claim 6 , wherein the provisioning login credentials are rendered obsolete and no valid provisioning login credentials are associated with the remote management controller when the remote management controller is transitioned to the provisioned mode.

8. The remote management controller of claim 6 , wherein further authentication by the program logic using the provisioning login credentials is disabled once the remote management controller is transitioned to the provisioned mode.

9. The remote management controller of claim 5 , wherein the program logic changes the provision mode value to indicate an unprovisioned mode when the remote management controller is transitioned from a provisioned mode to an unprovisioned mode.

10. The remote management controller of claim 9 , wherein new previously-unused provisioning login credentials are associated with the remote management controller when the remote management controller is transitioned from a provisioned mode to an unprovisioned mode.

11. The remote management controller of claim 1 , wherein the program logic enables the remote management controller to advertise correlatable system identifiers of a computer system associated with the remote management controller, thereby allowing the remote provisioning console to discover the computer system.

12. The remote management controller of claim 11 , wherein the correlatable system identifiers include a media access controller (MAC) address and a Globally Unique Identifier (GUID) associated with the computer system.

13. The remote management controller of claim 1 , wherein the program logic enables the remote provisioning console, once successfully authenticated, to configure the remote management controller.

14. The remote management controller of claim 1 , wherein the program logic enables the remote provisioning console once successfully authenticated, to set up one or more user accounts and corresponding authentication details in the remote management controller.

15. The remote management controller of claim 1 , wherein the remote management controller enables hands-free secure remote provisioning of the remote management controller.

16. The remote management controller of claim 1 , wherein the remote management controller is embedded in a network controller of a computer system.

17. The remote management controller of claim 1 , wherein the remote management controller is embedded in a motherboard of a computer system.

18. The remote management controller of claim 1 , wherein the remote management controller is embedded in a personal computer.

19. The remote management controller of claim 1 , wherein the remote management controller is embedded in a server.

20. The remote management controller of claim 1 , wherein the RAM is non-volatile RAM (NVRAM).

21. A computer program product comprising a non-transitory computer useable medium having program logic stored thereon that, when executed by a processor, causes the processor to perform a method for authenticating a remote provisioning console before allowing the remote provisioning console to provision a remote management controller, the method comprising:

receiving, at the remote management controller, login credentials from the remote provisioning console;

generating, at the remote management controller, provisioning login credentials from provisioning authentication data stored in a memory of the remote management controller; and

comparing, at the remote management controller, the received login credentials with the provisioning login credentials,

wherein the provisioning authentication data includes a device key associated with the remote management controller and a provision mode value representative of a provisioning mode of the remote management controller.

22. The computer program product of claim 21 , wherein the provision mode value indicates whether the remote management controller is currently provisioned or unprovisioned and a number of times that the remote management controller has been provisioned.

23. The computer program product of claim 21 , wherein said comparing comprises comparing a username and a password provided by the remote provisioning console with a known username and a password derived from the device key and the provision mode value of the remote management controller.

24. The computer program product of claim 21 , wherein the method further comprises:

changing the provision mode value after the remote provisioning console provisions the remote management controller, to transition the remote management controller to a provisioned mode.

25. The computer program product of claim 24 , wherein the provisioning login credentials are rendered obsolete and no valid provisioning login credentials are associated with the remote management controller when the remote management controller is transitioned to the provisioned mode.

26. The computer program product of claim 21 , wherein the method further comprises:

changing the provision mode value to indicate an unprovisioned mode when the remote management controller is transitioned from a provisioned mode to an unprovisioned mode.

27. The computer program product of claim 21 , wherein the method further comprises advertising correlatable system identifiers of a computer system associated with the remote management controller, thereby allowing the remote provisioning console to discover the computer system.

28. The computer program product of claim 27 , wherein the correlatable system identifiers include a media access controller (MAC) address and a Globally Unique Identifier (GUID) associated with the computer system.

29. A computer program product comprising a non-transitory computer useable medium having program logic stored thereon that, when executed by a processor, causes the processor to perform a method for extracting authentication data from a device, the method comprising:

reading a media access controller (MAC) address and a Globally Unique Identifier (GUID) associated with the device;

reading a device key associated with the device and a provision mode value representative of a provisioning mode of the device;

generating a provisioning password from the device key and the provision mode value; and

storing the MAC address and GUID with the generated provisioning password in a database.

30. The computer program product of claim 29 , wherein the method further comprises:

displaying the MAC address, GUID, and the provisioning password.

31. The computer program product of claim 29 , wherein the method further comprises:

changing the provision mode value to transition the device from a provisioned mode to an unprovisioned mode.

32. The computer program product of claim 29 , wherein the device includes a remote management controller.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE ERROR IN RECORDING THE MERGER IN THE INCORRECT US PATENT NO. 8,876,094 PREVIOUSLY RECORDED ON REEL 047351 FRAME 0384. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 8, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 049248/0558 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE MERGER PREVIOUSLY RECORDED AT REEL: 047230 FRAME: 0910. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047351/0384 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047230/0910 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2009
From: SWINDELL, ROBERT RAY
To: BROADCOM CORPORATION
Reel/Frame 023172/0553 →