IP Library Granted Patent US 10,382,396
Granted Patent B2
US 10,382,396 · App. 15/391,894 · Granted Aug 13, 2019

Utilizing management network for secured configuration and platform management

Inventors: Yuval Itkin (Zoran, IL); Tal Anker (Ramat Gan, IL); Dror Goldenberg (Zichron Yaakov, IL)
Assignee: Mellanox Technologies, Ltd.
H04L63/0236H04L41/28H04L63/10H04L63/101H04L63/18H04L63/20H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,396
App. No.
15/391,894
Granted
Aug 13, 2019
Kind
B2
Abstract

A network connection device having a security processor exchanges data traffic between a data network and a host computer via a network port. Security management data is exchanged exclusively between the security processor and a management network via a management network connectivity port that is inaccessible to the data traffic.

Claims (22)

1. A method for isolating security management data in a network, comprising the steps of:

connecting a host computer to a network connection device having a network port, access to a management network connectivity port, a sideband interface and a security processor;

connecting a baseboard management controller to the sideband interface, wherein the management network connectivity port is disposed in the baseboard management controller;

exchanging data traffic on a first path that extends between a data network and the host computer via the network port of the network connection device;

isolating security and network configuration functions of the network connection device from the host computer by exchanging security management data relevant to the security and network configuration functions between the security processor and a management host on a management network via a second path that extends from the security processor to the management host via the management network connectivity port;

directing the second path from the management network connectivity port to the security processor via the sideband interface; and

with the baseboard management controller producing traffic directed to the sideband interface for configuring the security processor.

2. The method according to claim 1 , wherein the management network connectivity port is integral with the network connection device.

3. The method according to claim 1 , wherein the security processor performs encryption and decryption of the data traffic.

4. The method according to claim 1 , wherein the security processor manages an access control list.

5. An apparatus, comprising:

a network interface device comprising:

a network port, configured for connection to a data network so as to exchange data traffic between the data network and a host computer on a first path;

a sideband interface; and

a security processor configured to control security and network configuration functions of the network interface device;

a baseboard management controller connected to the sideband interface;

a management network connectivity port in the baseboard management controller that is connectable to a management network, and operative for exchanging security management data relevant to the security and network configuration functions between the security processor and a management host on the management network via a second path that extends from the security processor to the management host via the management network connectivity port, wherein the basement management controller is operative for producing traffic directed to the sideband interface for configuring the security processor; and

a switch in the baseboard management controller that provides access for the security management data to the security processor on the second path via the sideband interface and operative to separate the security management data from traffic related to the host computer.

6. The apparatus according to claim 5 , wherein the baseboard management controller comprises:

a control interface for communicating with the host computer.

7. The apparatus according to claim 5 , wherein the security processor performs encryption and decryption of the data traffic.

8. The apparatus according to claim 5 , wherein the security processor manages an access control list.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 42962/0859 Recorded Jul 13, 2018
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MELLANOX TECHNOLOGIES, LTD.; MELLANOX TECHNOLOGIES TLV LTD.; MELLANOX TECHNOLOGIES SILICON PHOTONICS INC.
Reel/Frame 046551/0459 →
SECURITY INTEREST Recorded Jun 23, 2017
From: MELLANOX TECHNOLOGIES, LTD.; MELLANOX TECHNOLOGIES TLV LTD.; MELLANOX TECHNOLOGIES SILICON PHOTONICS INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 042962/0859 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2016
From: ITKIN, YUVAL; ANKER, TAL; GOLDENBERG, DROR
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 040779/0001 →
Continuity (1)
Related Publication 20180183758A1 · Jun 28, 2018
Cited By (4)
US 12,556,494 US 12,568,044 US 12,580,850 US 12,652,251