IP Library Granted Patent US 9,929,976
Granted Patent B2
US 9,929,976 · App. 15/270,418 · Granted Mar 27, 2018

System and method for data center security enhancements leveraging managed server SOCs

Inventors: Mark Davis (Austin, TX); David Borland (Austin, TX); Jason Hobbs (Leander, TX); Danny Marquette (Austin, TX); Thomas A. Volpe (Austin, TX); Ken Goss (Austin, TX)
Assignee: III HOLDINGS 2, LLC
H04L49/109H04L41/28H04L45/60H04L45/74H04L49/3009H04L49/351H04L49/356H04L63/0209H04L63/0236H04L63/1416H04L63/20H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,929,976
App. No.
15/270,418
Granted
Mar 27, 2018
Kind
B2
Abstract

A data center security system and method are provided that leverage server systems on a chip (SOCs) and/or server fabrics. In more detail, server interconnect fabrics may be leveraged and extended to dramatically improve security within a data center.

Claims (36)

1. A method comprising:

interconnecting nodes in a network, wherein each of the nodes includes a management processor, an application processor, and a routing header unit;

generating management information by the management processors in the interconnected nodes;

attaching a routing header to the management information to form a management information routing frame, wherein the routing header includes a management processor domain indicator which specifies that the management information routing frame is to remain within a management processor domain during routing,

determining a node in the network requires isolation from other nodes in the network; and

isolating the node determined to require isolation by a management processor corresponding to the node powering off an application processor for the node.

2. The method of claim 1 , wherein the management processor domain comprises the management processors but not the application processors.

3. The method of claim 1 , further comprising:

running the management processors within a security zone; and

running the application processors within a normal security zone.

4. The method of claim 1 , further comprising running, by the management processors, verified code.

5. The method of claim 1 , further comprising communicating, by the management processors, sensitive information with one another.

6. The method of claim 1 , further comprising providing, by the management processors, out-of-band security for the nodes.

7. A system on a chip (SoC) node comprising:

a management processor configured to generate management information;

an application processor coupled to the management processor;

a routing header unit configured to attach a routing header to the management information to form a management information routing frame, wherein the routing header includes a management processor domain indicator which specifies that the management information routing frame is to remain within a management processor domain during routing;

determine a node in the network requires isolation from other nodes in the network; and

isolate the node determined to require isolation by a management processor corresponding to the node powering off an application processor for the node.

8. The SoC node of claim 7 , wherein the management processor is further configured to run within a security zone, and wherein the application processor is configured to run within a normal security zone.

9. The SoC node of claim 7 , further comprising a media access control (MAC) associated with the management processor, wherein the MAC is configured to form a MAC packet for the management information, and wherein the routing header unit is further configured to attach the routing header to the MAC packet.

10. The SoC node of claim 7 , wherein the management processor runs an embedded operating system (OS), and wherein the application processor runs a standard OS.

11. The SoC node of claim 7 , wherein the management processor domain indicator is one bit.

12. The SoC node of claim 7 , wherein the management processor is in the management processor domain, and wherein the application processor is not in the management processor domain.

13. A system on a chip (SoC) node fabric comprising:

nodes interconnected to each other to form a fabric, wherein each node includes:

a management processor configured to generate management information;

an application processor coupled to the management processor; and

a routing header unit configured to attach a routing header to the management information to form a management information routing frame, wherein the routing header comprises a management processor domain indicator which specifies that the management information routing frame is to remain within a management processor domain during routing;

determine a node in the network requires isolation from other nodes in the network; and

isolate the node determined to require isolation by a management processor corresponding to the node powering off an application processor for the node.

14. The SoC node fabric of claim 13 , wherein the management processors run within a security zone, and wherein the application processors run within a normal security zone.

15. The SoC node fabric of claim 13 , wherein the management processor domain comprises the management processors but not the application processors.

16. The SoC node fabric of claim 13 , wherein the management processors are further configured to run verified code thereon.

17. The SoC node fabric of claim 13 , wherein the management processors provide out-of-band security for the nodes.

18. The SoC node fabric of claim 13 , wherein the management processor domain comprises a gateway media access control (MAC).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2017
From: SILICON VALLEY BANK
To: III HOLDINGS 2, LLC
Reel/Frame 043759/0175 →
Continuity (6)
Continuation 14334178 · Jul 17, 2014
Continuation 13475722 · May 18, 2012
Continuation In Part 12794996 · Jun 7, 2010
Provisional Application 61489569 · May 24, 2011
Provisional Application 61256723 · Oct 30, 2009
Related Publication 20170012899A1 · Jan 12, 2017