IP Library Granted Patent US 11,838,113
Granted Patent B2
US 11,838,113 · App. 16/656,009 · Granted Dec 5, 2023

Techniques to verify and authenticate resources in a data center computer environment

Inventors: Alberto J. Munoz (Los Altos, CA); Murugasamy K. Nachimuthu (Beaverton, OR); Mohan J. Kumar (Aloha, OR); Wojciech Powiertowski (Beaverton, OR); Sergiu D. Ghetie (Hillsboro, OR); Neeraj S. Upasani (Portland, OR); Sagar V. Dalvi (Hillsboro, OR); Chukwunenye S. Nnebe (Folsom, CA); Jeanne Guillory (Hillsboro, OR)
Assignee: INTEL CORPORATION
H04L43/08G02B6/3882G02B6/3893G02B6/3897G02B6/4292G02B6/4452G06F1/183G06F1/20G06F3/064G06F3/0613G06F3/0625G06F3/0653G06F3/0655G06F3/0664G06F3/0665G06F3/0673G06F3/0679G06F3/0683G06F3/0688G06F3/0689G06F8/65G06F9/30036G06F9/4401G06F9/544G06F12/109G06F12/1408G06F13/1668G06F13/409G06F13/4022G06F13/4068G06F15/161G06F16/9014G08C17/02G11C5/02G11C7/1072G11C11/56G11C14/0009H03M7/3086H03M7/4056H03M7/4081H04B10/25891H04L41/145H04L43/0817H04L43/0876H04L43/0894H04L49/00H04L49/25H04L49/357H04L49/45H04L67/02H04L67/306H04L69/04H04L69/329H04Q11/0003H05K7/1442B25J15/0014B65G1/0492G05D23/1921G05D23/2039G06F3/061G06F3/067G06F3/0611G06F3/0616G06F3/0619G06F3/0631G06F3/0638G06F3/0647G06F3/0658G06F3/0659G06F9/3887G06F9/505G06F9/5016G06F9/5044G06F9/5072G06F9/5077G06F11/141G06F11/3414G06F12/0862G06F12/0893G06F12/10G06F13/161G06F13/1694G06F13/42G06F13/4282G06F15/8061G06F2209/5019G06F2209/5022G06F2212/1008G06F2212/1024G06F2212/1041G06F2212/1044G06F2212/152G06F2212/202G06F2212/401G06F2212/402G06F2212/7207G06Q10/06G06Q10/06314G06Q10/087G06Q10/20G06Q50/04G07C5/008G08C2200/00G11C5/06H03M7/30H03M7/3084H03M7/40H03M7/4031H03M7/6005H03M7/6023H04B10/25H04J14/00H04L9/0643H04L9/14H04L9/3247H04L9/3263H04L12/2809H04L41/024H04L41/046H04L41/082H04L41/0813H04L41/0896H04L41/12H04L41/147H04L41/5019H04L43/065H04L43/16H04L45/02H04L45/52H04L47/24H04L47/38H04L47/765H04L47/782H04L47/805H04L47/82H04L47/823H04L49/15H04L49/555H04L61/00H04L67/10H04L67/1004H04L67/1008H04L67/1012H04L67/1014H04L67/1029H04L67/1034H04L67/1097H04L67/12H04L67/34H04L67/51H04Q1/04H04Q11/00H04Q11/0005H04Q11/0062H04Q11/0071H04Q2011/0037H04Q2011/0041H04Q2011/0052H04Q2011/0073H04Q2011/0079H04Q2011/0086H04Q2213/13523H04Q2213/13527H04W4/023H04W4/80H05K1/0203H05K1/181H05K5/0204H05K7/1418H05K7/1421H05K7/1422H05K7/1447H05K7/1461H05K7/1485H05K7/1487H05K7/1489H05K7/1491H05K7/1492H05K7/1498H05K7/2039H05K7/20709H05K7/20727H05K7/20736H05K7/20745H05K7/20836H05K13/0486H05K2201/066H05K2201/10121H05K2201/10159H05K2201/10189Y02D10/00Y02P90/30Y04S10/50Y04S10/52Y10S901/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,838,113
App. No.
16/656,009
Granted
Dec 5, 2023
Kind
B2
Abstract

Embodiments are generally directed apparatuses, methods, techniques and so forth to receive a sled manifest comprising identifiers for physical resources of a sled, receive results of an authentication and validation operations performed to authenticate and validate the physical resources of the sled, determine whether the results of the authentication and validation operations indicate the physical resources are authenticate or not authenticate. Further and in response to the determination that the results indicate the physical resources are authenticated, permit the physical resources to process a workload, and in response to the determination that the results indicate the physical resources are not authenticated, prevent the physical resources from processing the workload.

Claims (39)

1. An apparatus, comprising:

a processor; and

memory comprising instructions that when executed by the processor cause the processor to:

retrieve a sled manifest stored in a secure memory of a sled, the sled manifest to include hardware authentication information for multiple physical resources of the sled, the hardware authentication information to include a public key to verify each physical resource of the sled;

generate a nonce,

communicate the nonce to a physical resource of the sled,

receive a signed version of the nonce from the physical resource, the signed version of the nonce signed with a private key of the physical resource, and

determine whether the physical resource is authentic based in part on the signed version of the nonce and the public key of the physical resource included with the hardware authentication information from the sled manifest.

2. The apparatus of claim 1 , the memory comprising instructions that when executed by the processor cause the processor to permit the physical resources to process a workload in response to a determination that the physical resource is authentic.

3. The apparatus of claim 1 , the memory comprising instructions that when executed by the processor cause the processor to prevent the physical resources from processing a workload in response to a determination that the physical resource is not authentic.

4. The apparatus of claim 1 , the memory comprising instructions that when executed by the processor cause the processor to determine whether the physical resource is authentic based in part on the signed version of the nonce and the public key, the public key obtained from an original manufacturer of the physical resource.

5. The apparatus of claim 1 , the memory comprising instructions that when executed by the processor cause the processor to add an indication of the physical resources in a database in response to a determination that the physical resource is authentic.

6. The apparatus of claim 1 , the memory comprising instructions that when executed by the processor cause the processor to generate a composed node comprising the physical resources of the sled in response to a determination that the physical resource is authentic.

7. A non-transitory computer-readable storage medium, comprising a plurality of instructions, that when executed by processing circuitry, enable the processing circuitry to:

retrieve a sled manifest stored in a secure memory of a sled, the sled manifest to include hardware authentication information for multiple physical resources of the sled, the hardware authentication information to include a public key to verify each physical resource of the sled;

generate a nonce,

communicate the nonce to a physical resource of the sled,

receive a signed version of the nonce from the physical resource, the signed version of the nonce signed with a private key of the physical resource, and

determine whether the physical resource is authentic based in part on the signed version of the nonce and the public key of the physical resource included with the hardware authentication information from the sled manifest.

8. The non-transitory computer-readable storage medium of claim 7 , the plurality of instructions, when executed, enable the processing circuitry to permit the physical resources to process a workload in response to a determination that the physical resource is authentic.

9. The non-transitory computer-readable storage medium of claim 7 , the plurality of instructions, when executed, enable the processing circuitry to prevent the physical resources from processing a workload in response to a determination that the physical resource is not authentic.

10. The non-transitory computer-readable storage medium of claim 7 , the plurality of instructions, when executed, enable the processing circuitry to determine whether the physical resource is authentic based in part on the signed version of the nonce and the public key, the public key obtained from an original manufacturer of the physical resource.

11. The non-transitory computer-readable storage medium of claim 7 , the plurality of instructions, when executed, enable the processing circuitry to add an indication of the physical resources in a database in response to a determination that the physical resource is authentic.

12. The non-transitory computer-readable storage medium of claim 7 , the plurality of instructions, when executed, enable the processing circuitry to generate a composed node comprising the physical resources of the sled in response to a determination that the physical resource is authentic.

13. An apparatus comprising:

a physical resource of a sled;

circuitry; and

memory comprising instructions that when executed by the circuitry cause the circuitry to:

receive a nonce from a pod management controller,

sign the nonce with a private key of a keypair,

send the signed nonce to the pod management controller, the pod management controller to determine whether the physical resource is authentic based in part on the signed nonce and a public key of the keypair included with hardware authentication information from a sled manifest associated with the sled, the sled manifest stored in a secure memory of the sled.

14. The apparatus of claim 13 , the memory comprising instructions that when executed by the circuitry cause the circuitry to receive an indication to process, via the physical resource, a workload in response to a determination, by the pod management controller, that the physical resource is authentic.

15. The apparatus of claim 13 , wherein the public key of the keypair is available from an original manufacturer of the physical resource.

16. A non-transitory computer-readable storage medium, comprising a plurality of instructions, that when executed by circuitry of a physical resource of a sled, enable the circuitry to:

receive a nonce from a pod management controller;

sign the nonce with a private key of a keypair;

send the signed nonce to the pod management controller, the pod management controller to determine whether the physical resource is authentic based in part on the signed nonce and a public key of the keypair included with hardware authentication information from a sled manifest associated with the sled, the sled manifest stored in a secure memory of the sled.

17. The non-transitory computer-readable storage medium of claim 16 , the plurality of instructions, when executed, enable the circuitry to receive an indication to process, via the physical resource, a workload in response to a determination, by the pod management controller, that the physical resource is authentic.

18. The non-transitory computer-readable storage medium of claim 16 , wherein the public key of the keypair is available from an original manufacturer of the physical resource.

Continuity (5)
Continuation 15656798 · Jul 21, 2017
Provisional Application 62365969 · Jul 22, 2016
Provisional Application 62376859 · Aug 18, 2016
Provisional Application 62427268 · Nov 29, 2016
Related Publication 20200053438A1 · Feb 13, 2020
Cited By (1)
US 12,517,997