IP Library Granted Patent US 11,658,970
Granted Patent B2
US 11,658,970 · App. 17/019,523 · Granted May 23, 2023

Computing device infrastructure trust domain system

Inventors: Ravikanth Chaganti (Bangalore, IN); Dharmesh M. Patel (Round Rock, TX)
Assignee: Dell Products L.P.
H04L63/0876H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,658,970
App. No.
17/019,523
Granted
May 23, 2023
Kind
B2
Abstract

A computing device infrastructure trust domain system includes first and second computing devices included in a computing device infrastructure system. The second computing device stores authentication information specific to the computing device infrastructure system, and operates to receive a first communication broadcast by the first computing device, verify that the first communication includes the authentication information and, in response, add the first computing device to a trust domain and store a first computing device component hash value included in the first communication. When the second computing device subsequently receives a second communication from the first computing device, it determines whether the second communication includes the first computing device component hash value: If so, the second computing device removes the first computing device from the trust domain, if not, the second computing device performs at least one trust domain operation associated with the first computing device.

Claims (84)

1. A computing device infrastructure trust domain system, comprising:

a first computing device that is configured to operate as part of a computing device infrastructure system; and

a second computing device that is configured to operate as part of the computing device infrastructure system, that stores authentication information that is specific to the computing device infrastructure system, and that is configured to:

receive a first communication broadcast by the first computing device;

verify that the first communication includes the authentication information that is specific to the computing device infrastructure system and, in response:

add the first computing device to a trust domain; and

store, in the second computing device, a first computing device component hash value that is included in the first communication;

generate a second computing device component hash value using a respective second component identifier associated with at least one second component included in the second computing device;

determine that the second computing device component hash value and the first computing device component hash value configure the second computing device to operate as a primary trust domain device and the first computing device to operate as a secondary trust domain device; and

operate as the primary trust domain device to transmit a periodic request for the first computing device component hash value from the first computing device.

2. The system of claim 1 , wherein the first computing device is configured to operate as part of the computing device infrastructure system, stores the authentication information that is specific to the computing device infrastructure system, and is configured, in response to initialization of the computing device infrastructure system, to:

generate the first computing device component hash value using a respective first component identifier associated with at least one first component included in the first computing device; and

broadcast the first communication including the authentication information and the first computing device component hash value.

3. The system of claim 1 , wherein the second computing device is configured to generate the second computing device component hash value in response to initialization of the computing device infrastructure system and

broadcast a second communication including the authentication information and the second computing device component hash value.

4. The system of claim 1 , wherein the second computing device is configured to:

receive, subsequent to the first communication, a second communication from the first computing device; and

determine whether the second communication includes the first computing device component hash value and:

remove, in response to determining that the second communication does not include the first computing device component hash value, the first computing device from the trust domain; and

perform, in response to determining that the second communication includes the first computing device component hash value, at least one trust domain operation associated with the first computing device.

5. The system of claim 4 , wherein the second computing device is configured to:

receive, via a network from a management system, a first computing device component hash value change notification;

receive, subsequent to the second communication, a third communication broadcast by the first computing device; and

verify, in response to receiving the first computing device component hash value change notification, that the third communication includes the authentication information that is specific to the computing device infrastructure system and, in response:

store, in the second computing device, an updated first computing device component hash value that is included in the third communication.

6. The system of claim 1 , wherein the second computing device is configured to:

remove, in response to receiving no response to the periodic request for a time period, the first computing device from the trust domain; and

remove, in response to receiving a response to the periodic request that does not include the first computing device component hash value, the first computing device from the trust domain.

7. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide a trust domain engine that is configured to:

receive a first communication broadcast by a first computing device;

verify that the first communication includes authentication information that is specific to a computing device infrastructure system and, in response:

add the first computing device to a trust domain; and

store a first computing device component hash value that is included in the first communication;

generate a second computing device component hash value using a respective second component identifier associated with at least one second component included in the IHS;

determine that the second computing device component hash value and the first computing device component hash value configure the trust domain engine to operate as a primary trust domain device and the first computing device to operate as a secondary trust domain device; and

operate as the primary trust domain device to transmit a periodic request for the first computing device component hash value from the first computing device.

8. The IHS of claim 7 , wherein the trust domain engine is configured to generate the second computing device component hash value in response to initialization of the computing device infrastructure system and

broadcast a second communication including the authentication information and the second computing device component hash value.

9. The IHS of claim 8 , wherein the respective second component identifier associated with at least one second component included in the IHS includes:

a service tag associated with the IHS; and

a Media Access Controller (MAC) address used by a management controller device in the IHS.

10. The IHS of claim 8 , wherein the trust domain engine is configured to:

receive, subsequent to the first communication, a second communication from the first computing device; and

determine whether the second communication includes the first computing device component hash value and:

remove, in response to determining that the second communication does not include the first computing device component hash value, the first computing device from the trust domain; and

perform, in response to determining that the second communication includes the first computing device component hash value, at least one trust domain operation associated with the first computing device.

11. The IHS of claim 10 , wherein the trust domain engine is configured to:

receive, via a network from a management system, a first computing device component hash value change notification;

receive, subsequent to the second communication, a third communication broadcast by the first computing device; and

verify, in response to receiving the first computing device component hash value change notification, that the third communication includes the authentication information that is specific to the computing device infrastructure system and, in response:

store, in the second computing device, an updated first computing device component hash value that is included in the third communication.

12. The IHS of claim 7 , wherein the trust domain engine is configured to:

remove, in response to receiving no response to the periodic request for a time period, the first computing device from the trust domain; and

remove, in response to receiving a response to the periodic request that does not include the first computing device component hash value, the first computing device from the trust domain.

13. The IHS of claim 7 , wherein authentication information is generated based on an order identifier for the computing device infrastructure system.

14. A method for providing a trust domain for computing device infrastructure system, comprising:

receiving, by a second computing device, a first communication broadcast by a first computing device;

verifying, by the second computing device, that the first communication includes authentication information that is specific to a computing device infrastructure system and, in response:

adding, by the second computing device, the first computing device to a trust domain; and

storing, by the second computing device, a first computing device component hash value that is included in the first communication;

generating, by the second computing device, a second computing device component hash value using a respective second component identifier associated with at least one second component included in the second computing device

determining, by the second computing device, that the second computing device component hash value and the first computing device component hash value configure the second computing device to operate as a primary trust domain device and the first computing device to operate as a secondary trust domain device; and

operating, by the second computing device, as the primary trust domain device to transmit a periodic request for the first computing device component hash value from the first computing device.

15. The method of claim 14 , wherein the second computing device generates the second computing device component hash value in response to initialization of the computing device infrastructure system, and wherein the method further comprises:

broadcasting, by the second computing device in response to initialization of the computing device infrastructure system, a second communication including the authentication information and the second computing device component hash value.

16. The method of claim 15 , wherein the respective second component identifier associated with at least one second component included in the second computing device includes:

a service tag associated with the first computing device; and

a Media Access Controller (MAC) address used by a management controller device in the first computing device.

17. The method of claim 15 , further comprising:

receiving, by the second computing device subsequent to the first communication, a second communication from the first computing device; and

determining, by the second computing device, whether the second communication includes the first computing device component hash value and:

removing, by the second computing device in response to determining that the second communication does not include the first computing device component hash value, the first computing device from the trust domain; and

performing, by the second computing device in response to determining that the second communication includes the first computing device component hash value, at least one trust domain operation associated with the first computing device.

18. The method of claim 17 , further comprising:

receiving, by the second computing device via a network from a management system, a first computing device component hash value change notification;

receiving, by the second computing device subsequent to the second communication, a third communication broadcast by the first computing device; and

verifying, by the second computing device in response to receiving the first computing device component hash value change notification, that the third communication includes the authentication information that is specific to the computing device infrastructure system and, in response:

storing, by the second computing device, an updated first computing device component hash value that is included in the third communication.

19. The method of claim 14 , further comprising:

removing, by the second computing device in response to receiving no response to the periodic request for a time period, the first computing device from the trust domain; and

removing, by the second computing device in response to receiving a response to the periodic request that does not include the first computing device component hash value, the first computing device from the trust domain.

20. The method of claim 14 , wherein authentication information is generated based on an order identifier for the computing device infrastructure system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2020
From: CHAGANTI, RAVIKANTH; PATEL, DHARMESH M.
To: DELL PRODUCTS L.P.
Reel/Frame 053783/0936 →