IP Library Granted Patent US 10,728,030
Granted Patent B2
US 10,728,030 · App. 15/983,021 · Granted Jul 28, 2020

System and method for key management in computing clusters

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,728,030
App. No.
15/983,021
Granted
Jul 28, 2020
Kind
B2
Abstract

Cryptographic affinities are generated to improve security in server environments. One or more cryptographic affinities protect electronic data stored within a blade server. The cryptographic affinities are generated based on hashing a unique blade identifier and a unique identifier assigned to a network interface. The cryptographic affinities thus govern read, write, and other access operations. If any cryptographic affinity fails to match historical observance, then access to the blade server may be denied.

Claims (39)

1. A method of cryptographic security, comprising:

receiving, by an Ethernet controller, a read/write operation associated with a blade server installed in a chassis;

receiving, by the Ethernet controller, a blade identifier associated with the blade server installed in the chassis;

receiving, by the Ethernet controller, a host bus adapter identifier associated with a host bus adapter that communicates with the blade server installed in the chassis;

generating, by the Ethernet controller, a cryptographic affinity by hashing the blade identifier and the host bus adapter identifier using an electronic representation of a hashing algorithm;

comparing the cryptographic affinity to a historical value; and

in response to the cryptographic affinity failing to match the historical value, denying the read/write operation associated with the blade server.

2. The method of claim 1 , further comprising storing the cryptographic affinity in an electronic database.

3. The method of claim 1 , further comprising storing the cryptographic affinity in an electronic database, the electronic database electronically associating the cryptographic affinity and the blade identifier.

4. The method of claim 1 , further comprising retrieving the cryptographic affinity in response to a failure of at least one of the blade server and the host bus adapter.

5. The method of claim 1 , further comprising storing the cryptographic affinity in an electronic database, the electronic database electronically associating the cryptographic affinity to the blade identifier and to the host bus adapter identifier.

6. The method of claim 1 , further comprising denying an access to the blade server based on the cryptographic affinity.

7. The method of claim 1 , further comprising comparing the cryptographic affinity to an electronic database that stores historical values of the cryptographic affinity.

8. An apparatus, comprising:

a hardware processor; and

a memory device storing instructions, the instructions when executed causing the hardware processor to perform operations, the operations including:

receiving a read/write operation associated with a blade server installed in a chassis;

receiving a blade identifier associated with the blade server installed in the chassis;

receiving a host bus adapter identifier associated with a host bus adapter interfacing with the blade server;

generating a cryptographic affinity by hashing the blade identifier and the host bus adapter identifier using an electronic representation of a hashing algorithm;

comparing the cryptographic affinity to a historical value; and

in response to the cryptographic affinity failing to match the historical value, denying the read/write operation associated with the blade server.

9. The apparatus of claim 8 , wherein the operations further comprise storing the cryptographic affinity in an electronic database.

10. The apparatus of claim 8 , wherein the operations further comprise storing the cryptographic affinity in an electronic database, the electronic database electronically associating the cryptographic affinity and the blade identifier.

11. The apparatus of claim 8 , wherein the operations further comprise storing the cryptographic affinity in an electronic database, the electronic database electronically associating the cryptographic affinity and the host bus adapter identifier.

12. The apparatus of claim 8 , wherein the operations further comprise storing the cryptographic affinity in an electronic database, the electronic database electronically associating the cryptographic affinity to the blade identifier and to the host bus adapter identifier.

13. The apparatus of claim 8 , wherein the operations further comprise receiving a request to read an electronic data stored by the blade server.

14. The apparatus of claim 13 , wherein the operations further comprise denying the request to read the electronic data.

15. The apparatus of claim 8 , wherein the operations further comprise receiving a request to write an electronic data to the blade server.

16. The apparatus of claim 15 , wherein the operations further comprise denying the request to write the electronic data.

17. A memory device storing instructions that when executed cause a hardware processor to perform operations, the operations comprising:

receiving a read/write operation associated with a blade server installed in a chassis;

receiving a blade identifier sent from the blade server installed in the chassis;

retrieving a host bus adapter identifier associated with a host bus adapter interfacing with the blade server;

generating a cryptographic affinity by hashing the blade identifier and the host bus adapter identifier using an electronic representation of a hashing algorithm; and

if the cryptographic affinity fails to match the historical value, then denying the read/write operation associated with the blade server.

18. The memory device of claim 17 , wherein the operations further comprise denying an access to the blade server.

19. The memory device of claim 17 , wherein the operations further comprise denying a read operation.

20. The memory device of claim 17 , wherein the operations further comprise denying a write operation.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2019
From: VISHWANATH, MANJUNATH; NELOGAL, CHANDRASHEKAR; GUPTA, CHITRAK; G, PAVAN KUMAR
To: DELL PRODUCTS, LP
Reel/Frame 049030/0777 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →