IP Library Granted Patent US 10,116,653
Granted Patent B2
US 10,116,653 · App. 15/227,375 · Granted Oct 30, 2018

System and method for securing IPMI remote authenticated key-exchange protocol (RAKP) over hash cracks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,653
App. No.
15/227,375
Granted
Oct 30, 2018
Kind
B2
Abstract

Systems and methods for continuously secure Intelligent Platform Management Interface (IPMI) Remote Authenticated Key-Exchange Protocol (RAKP) over hash cracks. The system includes a management controller, which may receive, from a computing device via a network under the IPMI RAKP protocol, a credential information including a password. In response, the management controller may generate a hash information based on the password, and send the hash information to the computing device. Since the hash information may be used to crack the password, after a time interval from sending the hash information to the computing device, the management controller may change the password to a new password, in order to maintain the security of the password.

Claims (62)

1. A system, comprising:

a management controller, comprising a processor and a non-volatile memory storing computer executable code, wherein the computer executable code, when executed at the processor of the management controller, is configured to:

receive, from a computing device via a network under an intelligent platform management interface (IPMI) remote authenticated key-exchange protocol (RAKP), a credential information comprising a password;

in response to receiving the credential information, generate a hash information based on the password, and send the hash information to the computing device via the network under the IPMI RAKP; and

after a time interval from sending the hash information to the computing device, change the password to a new password,

wherein the time interval is determined based on strength parameters of the password, including:

a length of the password;

whether the password includes symbols;

whether the password includes numbers;

whether the password includes lowercase characters; and

whether the password includes uppercase characters.

2. The system of claim 1 , wherein the management controller is a baseboard management controller (BMC).

3. The system of claim 1 , wherein the computer executable code, when executed at the processor of the management controller, is further configured to:

reset the time interval when the password is changed.

4. The system of claim 1 , wherein the computer executable code, when executed at the processor of the management controller, is further configured to:

send an email comprising the new password to a user.

5. The system of claim 4 , wherein the new password is a temporary password, and the email further comprises a request to the user to manually change the temporary password.

6. The system of claim 1 , wherein the computer executable code comprises:

a data store, configured to store information of rules for generating the new password;

an authentication module, configured to receive the credential information from the computing device, generate the hash information, and send the hash information to the computing device; and

a password generation module, configured to change the password to the new password by generating the new password based on the rules for generating the new password stored in the data store, and replacing the password with the new password being generated.

7. The system of claim 6 , wherein the computer executable code further comprises:

a time interval determination module, configured to determine the time interval based on a strength of the new password, wherein the strength of the new password is determined by the strength parameters of the new password.

8. The system of claim 1 , wherein the time interval is determined by:

calculating, using the strength parameters of the password, a time period required for a hacker to crack the hash information; and

determining the time interval to be a predetermined fraction of the time period.

9. The system of claim 8 , wherein the predetermined fraction is 25%.

10. A method for secure intelligent platform management interface (IPMI) remote authenticated key-exchange protocol (RAKP) of a management controller, comprising:

receiving, by the management controller, a credential information comprising a password from a computing device via a network under an IPMI RAKP; and

in response to receiving the credential information, generating, by the management controller, a hash information based on the password, and sending the hash information to the computing device via the network under the IPMI RAKP; and

after a time interval from sending the hash information to the computing device, changing, by the management controller, the password to a new password,

wherein the time interval is determined based on strength parameters of the password, including:

a length of the password;

whether the password includes symbols;

whether the password includes numbers;

whether the password includes lowercase characters; and

whether the password includes uppercase characters.

11. The method of claim 10 , wherein the management controller is a baseboard management controller (BMC).

12. The method of claim 10 , further comprising:

resetting the time interval if the password is changed.

13. The method of claim 10 , further comprising:

sending, by the management controller, an email comprising the new password to a user.

14. The method of claim 13 , wherein the new password is a temporary password, and the email further comprises a request to the user to manually change the temporary password.

15. The method of claim 10 , wherein the management controller stores information of rules for generating the new password, and the password is changed to the new password by:

generating the new password based on the rules for generating the new password stored in the data store; and

replacing the password with the new password being generated.

16. The method of claim 10 , wherein the time interval is determined based on a strength of the new password, wherein the strength of the new password is determined by the strength parameters of the new password.

17. A non-transitory computer readable medium storing computer executable code, wherein the computer executable code, when executed at a processor of a management controller, is configured to:

receive, from a computing device via a network under an intelligent platform management interface (IPMI) remote authenticated key-exchange protocol (RAKP), a credential information comprising a password;

in response to receiving the credential information, generate a hash information based on the password, and send the hash information to the computing device via the network under the IPMI RAKP; and

after a time interval from sending the hash information to the computing device, change the password to a new password,

wherein the time interval is determined based on strength parameters of the password, including:

a length of the password;

whether the password includes symbols;

whether the password includes numbers;

whether the password includes lowercase characters; and

whether the password includes uppercase characters.

18. The non-transitory computer readable medium of claim 17 , wherein the computer executable code, when executed at the processor of the management controller, is further configured to:

reset the time interval when the password is changed.

19. The non-transitory computer readable medium of claim 17 , wherein the computer executable code, when executed at the processor of the management controller, is further configured to:

send an email comprising the new password to a user.

20. The non-transitory computer readable medium of claim 19 , wherein the new password is a temporary password, and the email further comprises a request to the user to manually change the temporary password.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Oct 23, 2024
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: BAIN CAPITAL CREDIT, LP, AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 069229/0834 →
RELEASE OF SECURITY INTEREST Recorded Oct 17, 2024
From: MIDCAP FINANCIAL TRUST
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 069205/0795 →
SECURITY INTEREST Recorded May 6, 2019
From: AMERICAN MEGATRENDS INTERNATIONAL, LLC
To: MIDCAP FINANCIAL TRUST, AS COLLATERAL AGENT
Reel/Frame 049087/0266 →
ENTITY CONVERSION Recorded Apr 15, 2019
From: AMERICAN MEGATRENDS, INC.
To: AMERICAN MEGATRENDS INTERNATIONAL, LLC
Reel/Frame 049091/0973 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2016
From: RATHINESWARAN, CHANDRASEKAR; VENKATARAMAN, ARUNA
To: AMERICAN MEGATRENDS, INC.
Reel/Frame 039332/0758 →