IP Library Granted Patent US 10,148,669
Granted Patent B2
US 10,148,669 · App. 14/271,992 · Granted Dec 4, 2018

Out-of-band encryption key management system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,669
App. No.
14/271,992
Granted
Dec 4, 2018
Kind
B2
Abstract

An encryption key management system includes an encryption IHS that is coupled to a network. The encryption key management system also includes a host processing system. An off-host processing system in the encryption key management system is coupled to the host processing system and is coupled to the encryption IHS through the network. The off-host processing system provides an encryption key request to the encryption IHS through the network, receives an encryption key from the encryption IHS through the network and stores the encryption key, provides the encryption key to the host processing system in response to authenticating a user, and revokes the encryption key in response to a revocation instruction received from the encryption IHS through the network. The providing the request, and the receiving, providing, and revoking the encryption key may be performed by the off-host processing system while the host-processing system is not in an operating mode.

Claims (58)

1. An encryption key management system, comprising:

an encryption information handling system (IHS) that is coupled to a network;

a user IHS that is coupled to the network and that includes a user IHS chassis that houses:

a network interface controller that includes a first network controller that is coupled to the network and a second network controller that is coupled to the network;

a host processing system that includes a host processor and a host memory that is coupled to the host processor, wherein the host processing system is coupled to the network via the first network controller such that the host processing system only has access to the network through the first network controller; and

an off-host processing system that includes an off-host processor and an off-host memory that is coupled to the off-host processor and that is not accessible by the host processor, wherein the off-host processing system is coupled to the host processing system via a bus, and coupled to the encryption IHS through the network via the second network controller such that the off-host processing system only has access to the network through the second network controller, and wherein the first network controller and the second network controller allow the host processing system and the off-host processing system to access the network at the same time when the host processing system is operational, and wherein the off-host processing system is configured to:

provide an encryption key request to the encryption IHS through the network;

receive an encryption key from the encryption IHS through the network and store the encryption key in the off-host memory such that the encryption key is not accessible by the host processor;

provide the encryption key to the host processing system over the bus in response to authenticating a user such that the encryption key is accessible by the host processor; and

revoke the encryption key in response to a revocation instruction that is received from the encryption IHS through the network.

2. The system of claim 1 , wherein the second network controller is configured to forward the encryption key request from the off-host processing system to the encryption IHS, and wherein the second network controller is configured to forward the encryption key from the encryption IHS to the off-host processing system.

3. The system of claim 2 , wherein the user IHS chassis further houses:

an embedded controller system that couples the off-host processing system to the second network controller, wherein the embedded controller system is configured to forward the encryption key request from the off-host processing system to the second network controller, and wherein the embedded controller system is configured to forward the encryption key from the second network controller to the off-host processing system.

4. The system of claim 1 , wherein the providing the encryption key request, receiving the encryption key, providing the encryption key, and revoking the encryption key are performed by the off-host processing system while the host processing system is not in an operating mode.

5. The system of claim 1 , wherein the encryption IHS is configured, without a request from the off-host processing system, to update one or more encryption keys on the off-host processing system while the host processing system is not in an operating mode.

6. The system of claim 1 , wherein the host processing system is configured to use the encryption key to decrypt encrypted information on a storage device.

7. The system of claim 1 , wherein the host processing system and the off-host processing system are each located in a user IHS chassis.

8. An information handling system (IHS), comprising:

an IHS chassis that houses:

a network interface controller that includes a first network controller that is coupled to the network and a second network controller that is coupled to the network;

an IHS host processing system that includes a host processor and a host memory that is coupled to the host processor, wherein the host processor is coupled to the network via the first network controller such that the host processing system only has access to the network through the first network controller; and

an off-host processing system that includes an off-host processor and an off-host memory that is coupled to the off-host processor and that is not accessible by the host processor, wherein the off-host processing system is coupled to the IHS host processing system via a bus, and coupled to the network via the second network controller such that the off-host processor only has access to the network through the second network controller, and wherein the first network controller and the second network controller allow the IHS host processing system and the off-host processing system to access the network at the same time when the IHS host processing system is operational, and wherein the off-host processing system is configured to:

provide an encryption key request through the second network controller to an encryption IHS;

receive an encryption key from the encryption IHS through the second network controller and store the encryption key in the off-host memory such that the encryption key is not accessible by the host processor;

provide the encryption key to the IHS host processing system via the bus in response to authenticating a user such that the encryption key is accessible by the host processor; and

revoke the encryption key in response to a revocation instruction that is received through the second network controller from the encryption IHS.

9. The IHS of claim 8 , wherein the IHS chassis further houses:

an embedded controller system that couples the off-host processing system to the second network controller, wherein the embedded controller system is configured to forward the encryption key request from the off-host processing system to the second network controller, and wherein the embedded controller system is configured to forward the encryption key from the second network controller to the off-host processing system.

10. The IHS of claim 8 , wherein the providing the encryption key request, receiving the encryption key, providing the encryption key, and revoking the encryption key are performed by the off-host processing system while the IHS host processing system is not in an operating mode.

11. The IHS of claim 8 , wherein

the encryption IHS is coupled through the network to the first network controller and the second network controller.

12. The IHS of claim 8 , wherein the encryption IHS is configured, without a request from the off-host processing system, to update one or more encryption keys on the off-host processing system while the IHS host processing system is not in an operating mode.

13. The IHS of claim 8 , further comprising:

a storage device coupled to the IHS host processing system, wherein the IHS host processing system is configured to use the encryption key to decrypt encrypted information on the storage device.

14. The IHS of claim 8 , further comprising:

an IHS chassis, wherein the IHS host processing system and the off-host processing system are each located in an IHS chassis.

15. A method for managing encryption keys, comprising:

providing, by an off-host processing system in a computing device, an encryption key request to an encryption IHS through a network, wherein the computing device includes a computing device chassis that houses:

(1) a host processing system with a host processor;

(2) a first network controller that provides the only access to the network for the host processor;

(3) a host memory that is coupled to the host processor;

(4) the off-host processing system with an off-host processor;

(5) a second network controller that provides the only access to the network for the off-host processor, wherein the first network controller and the second network controller allow the host processor and the off-host processor to access the network at the same time when the host processor is operational; and

(6) an off-host memory that is coupled to the off-host processor and not accessible by the host processor;

receiving, by the off-host processing system, an encryption key from the encryption IHS through the network via the second network controller and storing the encryption key in the off-host memory such that the encryption key is not accessible by the host processor;

providing, by the off-host processing system, the encryption key to a host processing system via the bus in response to authenticating a user such that the encryption key is accessible by the host processor; and

revoking, by the off-host processing system, the encryption key in response to a revocation instruction that is received from the encryption IHS through the network.

16. The method of claim 15 , further comprising:

forwarding, by the second network controller that couples the off-host processing system to the network, the encryption key request from the off-host processing system to the encryption IHS; and

forwarding, by the second network controller, the encryption key from the encryption IHS to the off-host processing system.

17. The method of claim 16 , further comprising:

forwarding, by an embedded controller system that is housed in the computer device chassis and that couples the off-host processing system to the second network controller, the encryption key request from the off-host processing system to the second network controller; and

forwarding, by the embedded controller system, the encryption key from the second network controller to the off-host processing system.

18. The method of claim 15 , wherein the providing the encryption key request, receiving the encryption key, providing the encryption key, and revoking the encryption key are performed by the off-host processing system while the host processing system is not in an operating mode.

19. The method of claim 15 , further comprising:

updating, by the encryption IHS without receiving a request from the off-host processing system, one or more encryption keys on the off-host processing system while the host processing system is not in an operating mode.

20. The method of claim 15 , further comprising:

decrypting, by the host processing system using the encryption key, encrypted information on a storage device.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 033625 FRAME 0688 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0757 →
RELEASE OF REEL 033625 FRAME 0748 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0050 →
RELEASE OF REEL 033625 FRAME 0711 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.
Reel/Frame 040016/0903 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 033625/0748 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033625/0711 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 033625/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2014
From: HAMLIN, DANIEL; ROBISON, CHARLES
To: DELL PRODUCTS L.P.
Reel/Frame 033130/0373 →