IP Library Granted Patent US 10,148,444
Granted Patent B2
US 10,148,444 · App. 15/228,602 · Granted Dec 4, 2018

Systems and methods for storing administrator secrets in management controller-owned cryptoprocessor

Inventors: Johan Rahardjo (Austin, TX); Mukund P. Khatri (Austin, TX); Theodore S. Webb (Austin, TX)
Assignee: Dell Products L.P.
H04L9/3263H04L9/0897H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,444
App. No.
15/228,602
Granted
Dec 4, 2018
Kind
B2
Abstract

A method may include storing a first set of secrets associated with an information handling system in a credential vault of a management controller configured to be coupled to a processor of a host system of the information handling system in order to provide management of the information handling system via management traffic communicated between the management controller and an external management network such that the first set of secrets are accessible responsive to a verified boot of the management controller and storing a second set of secrets associated with the information handling system in a storage of a cryptoprocessor owned by the management controller such that access to the second set of secrets may be granted in response to an administrator's provision of authorization to the cryptoprocessor, and such that access to the second set of secrets is prevented during runtime of the host system in absence of authorization.

Claims (29)

1. An information handling system comprising:

a host system comprising a host system processor;

a management controller communicatively coupled to the host system processor and configured to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, the management controller being capable of providing the out-of-band management when the information handling system is in a powered-off state, the management controller comprising:

a management controller processor; and

a credential vault communicatively coupled to the management controller processor and configured to store a first set of secrets associated with the information handling system, wherein the first set of secrets are accessible in response to a hardware-verified boot of the management controller; and

a cryptoprocessor communicatively coupled to and owned by the management controller processor, the cryptoprocessor comprising a storage configured to store a second set of secrets associated with the information handling system such that access to the second set of secrets may be granted in response to an administrator's provision of a verified authorization to the cryptoprocessor, and such that access to the second set of secrets is prevented during runtime of the host system if the verified authorization is not present.

2. The information handling system of claim 1 , wherein the cryptoprocessor comprises a Trusted Platform Module.

3. The information handling system of claim 1 , wherein the management controller comprises a baseboard management controller.

4. The information handling system of claim 1 , wherein the second set of secrets comprises credentials for performing particular management functions not enabled by the first set of secrets.

5. A method comprising:

communicatively coupling a credential vault to a management controller processor of a management controller configured to be coupled to a host system processor of a host system of an information handling system in order to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, the management controller being capable of providing the out-of-band management when the information handling system is in a powered-off state, wherein the credential vault is configured to store a first set of secrets associated with the information handling system, wherein the first set of secrets are accessible in response to a hardware-verified boot of the management controller; and

communicatively coupling a cryptoprocessor to the management controller processor such that it is owned by the management controller processor, the cryptoprocessor comprising a storage configured to store a second set of secrets associated with the information handling system such that access to the second set of secrets may be granted in response to an administrator's provision of a verified authorization to the cryptoprocessor, and such that access to the second set of secrets is prevented during runtime of the host system if the verified authorization is not present.

6. The method of claim 5 , wherein the cryptoprocessor comprises a Trusted Platform Module.

7. The method of claim 5 , wherein the management controller comprises a baseboard management controller.

8. The method of claim 5 , wherein the second set of secrets comprises credentials for performing particular management functions not enabled by the first set of secrets.

9. A method comprising:

storing a first set of secrets associated with an information handling system in a credential vault integral to a management controller configured to be coupled to a host system processor of a host system of the information handling system in order to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system such that the first set of secrets are accessible in response to a hardware-verified boot of the management controller, the management controller being capable of providing the out-of-band management when the information handling system is in a powered-off state; and

storing a second set of secrets associated with the information handling system in a storage of a cryptoprocessor communicatively coupled to and owned by the management controller such that access to the second set of secrets may be granted in response to an administrator's provision of a verified authorization to the cryptoprocessor, and such that access to the second set of secrets is prevented during runtime of the host system if the verified authorization is not present.

10. The method of claim 9 , wherein the cryptoprocessor comprises a Trusted Platform Module.

11. The method of claim 9 , wherein the management controller comprises a baseboard management controller.

12. The method of claim 9 , wherein the second set of secrets comprises credentials for performing particular management functions not enabled by the first set of secrets.

13. An article of manufacture comprising:

a non-transitory computer-readable medium; and

computer-executable instructions carried on the computer-readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

store a first set of secrets associated with an information handling system in a credential vault integral to a management controller configured to be coupled to a host system processor of a host system of an information handling system in order to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system such that the first set of secrets are accessible in response to a hardware-verified boot of the management controller, the management controller being capable of providing the out-of-band management when the information handling system is in a powered-off state; and

store a second set of secrets associated with the information handling system in a storage of a cryptoprocessor communicatively coupled to and owned by the management controller such that access to the second set of secrets may be granted in response to an administrator's provision of a verified authorization to the cryptoprocessor, and such that access to the second set of secrets is prevented during runtime of the host system if the verified authorization is not present.

14. The article of claim 13 , wherein the cryptoprocessor comprises a Trusted Platform Module.

15. The article of claim 13 , wherein the management controller comprises a baseboard management controller.

16. The article of claim 13 , wherein the second set of secrets comprises credentials for performing particular management functions not enabled by the first set of secrets.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2016
From: RAHARDJO, JOHAN; KHATRI, MUKUND P.; WEBB, THEODORE S.
To: DELL PRODUCTS L.P.
Reel/Frame 039345/0887 →
Continuity (1)
Related Publication 20180041344A1 · Feb 8, 2018