IP Library › Granted Patent US 11,237,986
Granted Patent B1
US 11,237,986 · App. 16/678,866 · Granted Feb 1, 2022

Method and apparatus for side-band management of security for a server computer

Inventor: Sofin Raskin (Los Altos, CA)
Assignee: JANUS TECHNOLOGIES, INC.
G06F12/1408G06F9/4416G06F9/45558G06F21/62H04L63/02H04L63/06H04L63/062H04L63/10H04L63/20G06F21/70G06F21/71G06F21/74G06F2009/45587G06F2009/45595G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,237,986
App. No.
16/678,866
Granted
Feb 1, 2022
Kind
B1
Abstract

The present embodiments relate to methods and apparatuses for side-band management of security for server computers. According to certain aspects, such management is directed to the security of data that is stored under the local control of the server, as well as data that flows through the network ports of the server. Such locally stored data is secured by encryption, and the encryption keys are managed by a management entity that is separate from the server. The management entity can also manage the security of network data flowing through the server using its own configuration of network security applications such as firewalls, monitors and filters.

Claims (9)

1. A server system comprising:

a host complex comprising memory for storing instructions for running software applications, wherein the software applications include one or more virtual machines;

a secure complex; and

a network connection that is configured with a policy by an external management entity that communicates with the secure complex, wherein the secure complex is configured to block certain network communications by the software applications using the network connection based on the policy,

wherein the network connection comprises one or more interface endpoints, and wherein the host complex further runs device driver software for communicating with the interface endpoints, and

wherein the secure complex is configured to prevent the host complex from enumerating the interface endpoints unless and until the external management entity allows, and to perform statistics on certain other network communications by the software applications using the network connection, wherein the policy specifies a particular one of the one or more virtual machines for performing statistics.

2. The server system according to claim 1 , wherein the software applications include one or more virtual machines.

3. The server system according to claim 2 , wherein the policy specifies a particular one of the one or more virtual machines for blocking of network communications.

4. The server system according to claim 1 , wherein the interface endpoints comprise peripheral connect interface express (PCIe) endpoints.

Continuity (1)
Division 15059077 · Mar 2, 2016
Cited By (1)
US 12,639,479