IP Library Granted Patent US 10,778,650
Granted Patent B2
US 10,778,650 · App. 15/239,195 · Granted Sep 15, 2020

Systems and methods for management domain attestation service

Inventors: Johan Rahardjo (Austin, TX); Mukund P. Khatri (Austin, TX); Michael J. Stumpf (Cedar Park, TX)
Assignee: Dell Products L.P.
H04L63/0428H04L9/0877H04L9/3234H04L41/28H04L63/102H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,650
App. No.
15/239,195
Granted
Sep 15, 2020
Kind
B2
Abstract

In accordance with embodiments of the present disclosure, a method may include: (i) retrieving a profile from a management controller of an information handling system, the management controller configured to provide management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, and the profile including data regarding a configuration of the management controller; (ii) comparing the profile to one or more golden profiles to determine whether security of the management controller has been compromised; (iii) responsive to the profile matching a golden profile of the one or more golden profiles, permitting the management controller to continue execution; and (iv) responsive to the profile failing to match a golden profile of the one or more golden profiles, taking remedial action with respect to the management controller.

Claims (34)

1. An information handling system comprising:

a processor; and

a program of instructions embodied in non-transitory computer-readable media, the program of instructions configured to, when executed by the processor:

retrieve a profile from a management controller of a second information handling system, the management controller configured to provide out-of-band management of the second information handling system via management traffic communicated between the management controller and a dedicated management network external to the second information handling system, the out-of-band management including management of the second information handling system when the second information handling system is in a powered-off state, and the profile including data regarding a configuration of the management controller, wherein the profile includes data regarding a runtime configuration of the management controller, the data including at least one value that was stored in a selected memory location of the management controller during runtime execution of the management controller;

compare the profile to one or more golden profiles to determine whether security of the management controller has been compromised;

responsive to the profile matching a golden profile of the one or more golden profiles, permit the management controller to continue execution; and

responsive to the profile failing to match a golden profile of the one or more golden profiles, take remedial action with respect to the management controller.

2. The information handling system of claim 1 , wherein the profile is embodied in a platform control register associated with a cryptoprocessor associated with the management controller.

3. The information handling system of claim 1 , wherein the profile is encrypted by a private key of a public/private key pair, and the program of instructions is further configured to decrypt the profile with a public key of the public/private key pair to validate the profile before comparison to the one or more golden profiles.

4. The information handling system of claim 1 , wherein the profile further includes data regarding a boot-time configuration of the management controller.

5. The information handling system of claim 1 , wherein the remedial action comprises segregating the management controller into an untrusted subnet of the dedicated management network.

6. The information handling system of claim 5 , wherein the remedial action further comprises segregating a host system of the second information handling system into an untrusted subnet of a data network coupled to the host system.

7. A method comprising:

retrieving a profile from a management controller of an information handling system, the management controller configured to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, the out-of-band management including management of the information handling system when the information handling system is in a powered-off state, and the profile including data regarding a configuration of the management controller, wherein the profile includes data regarding a runtime configuration of the management controller, the data including at least one value that was stored in a selected memory location of the management controller during runtime execution of the management controller;

comparing the profile to one or more golden profiles to determine whether security of the management controller has been compromised;

responsive to the profile matching a golden profile of the one or more golden profiles, permitting the management controller to continue execution; and

responsive to the profile failing to match a golden profile of the one or more golden profiles, taking remedial action with respect to the management controller.

8. The method of claim 7 , wherein the profile is embodied in a platform control register associated with a cryptoprocessor associated with the management controller.

9. The method of claim 7 , wherein the profile is encrypted by a private key of a public/private key pair, and the method further comprises decrypting the profile with a public key of the public/private key pair to validate the profile before comparison to the one or more golden profiles.

10. The method of claim 7 , wherein the profile further includes data regarding a boot-time configuration of the management controller.

11. The method of claim 7 , wherein the remedial action comprises segregating the management controller into an untrusted subnet of the dedicated management network.

12. The method of claim 11 , wherein the remedial action further comprises segregating a host system of the information handling system into an untrusted subnet of a data network coupled to the host system.

13. An article of manufacture comprising:

a non-transitory computer-readable medium; and

computer-executable instructions carried on the computer-readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

retrieve a profile from a management controller of an information handling system, the management controller configured to provide out-of-band management of the information handling system via management traffic communicated between the management controller and a dedicated management network external to the information handling system, the out-of-band management including management of the information handling system when the information handling system is in a powered-off state, and the profile including data regarding a configuration of the management controller, wherein the profile includes data regarding a runtime configuration of the management controller, the data including at least one value that was stored in a selected memory location of the management controller during runtime execution of the management controller;

compare the profile to one or more golden profiles to determine whether security of the management controller has been compromised;

responsive to the profile matching a golden profile of the one or more golden profiles, permit the management controller to continue execution; and

responsive to the profile failing to match a golden profile of the one or more golden profiles, take remedial action with respect to the management controller.

14. The article of claim 13 , wherein the profile is embodied in a platform control register associated with a cryptoprocessor associated with the management controller.

15. The article of claim 13 , wherein the profile is encrypted by a private key of a public/private key pair, and the instructions further cause the processor to decrypt the profile with a public key of the public/private key pair to validate the profile before comparison to the one or more golden profiles.

16. The article of claim 13 , wherein the profile further includes data regarding a boot-time configuration of the management controller.

17. The article of claim 13 , wherein the remedial action comprises segregating the management controller into an untrusted subnet of the dedicated management network.

18. The article of claim 17 , wherein the remedial action further comprises segregating a host system of the information handling system into an untrusted subnet of a data network coupled to the host system.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2016
From: RAHARDJO, JOHAN; KHATRI, MUKUND P.; STUMPF, MICHAEL J.
To: DELL PRODUCTS L.P.
Reel/Frame 039467/0379 →
Continuity (1)
Related Publication 20180054422A1 · Feb 22, 2018