IP Library › Granted Patent US 11,868,474
Granted Patent B2
US 11,868,474 · App. 17/280,507 · Granted Jan 9, 2024

Securing node groups

Inventors: Nigel Edwards (Bristol, GB); Michael R. Krause (Boulder Creek, CA); Melvin Benedict (Magnolia, TX); Ludovic Emmanuel Paul Noel Jacquin (Bristol, GB); Luis Luciani (Tomball, TX); Thomas Laffey (Roseville, CA); Theofrastos Koulouris (Bristol, GB); Shiva Dasari (Houston, TX)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/57G06F21/32H04L9/0816H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,868,474
App. No.
17/280,507
Granted
Jan 9, 2024
Kind
B2
Abstract

A method for securing a plurality of compute nodes includes authenticating a hardware architecture of each of a plurality of components of the compute nodes. The method also includes authenticating a firmware of each of the plurality of components. Further, the method includes generating an authentication database comprising a plurality of authentication descriptions that are based on the authenticated hardware architecture and the authenticated firmware. Additionally, a policy for securing a specified subset of the plurality of compute nodes is implemented by using the authentication database.

Claims (55)

1. A method for securing a plurality of compute nodes, comprising:

authenticating a hardware architecture of each of a plurality of components of the compute nodes;

authenticating a firmware of each of the plurality of components; and

generating an authentication database comprising a plurality of authentication descriptions that are based on the authenticated hardware architecture and the authenticated firmware, wherein a policy for securing a specified subset of the plurality of compute nodes is implemented by using the authentication database.

2. The method of claim 1 , further comprising implementing the policy by using (i) an operation of an application program interface for authenticating compute node groups, and (ii) operating the authentication database.

3. The method of claim 1 , wherein one of the compute nodes comprises a controller that is connected to the plurality of components, and wherein the controller authenticates the hardware architecture of the plurality of components and authenticates the firmware of the plurality of components, wherein the controller compares the authenticated hardware architecture and the authenticated firmware with one or more previous authentications to detect changes to the hardware architecture and the firmware.

4. The method of claim 1 , wherein one of the plurality of compute nodes comprises a baseboard management controller and a computer processor, and wherein the baseboard management controller authenticates the hardware architecture of the computer processor and authenticates the firmware of the computer processor.

5. The method of claim 1 , comprising generating a firmware measurement certificate for each layer of firmware of the plurality of components, wherein:

a core root of trust generates the firmware measurement certificate for a first layer of the firmware;

the firmware measurement certificate for the first layer of firmware specifies a trusted certification authority; and

authenticating the firmware is based on the firmware measurement certificate.

6. The method of claim 5 , wherein:

the firmware of the plurality of components operates the plurality of components;

the firmware measurement certificate comprises an attribute certificate; and

the firmware measurement certificate comprises:

a cumulative hash of the layer of firmware, wherein the cumulative hash comprises a concatenation of:

a hash of the layer of firmware; and

a hash of each one or more lower layers of the firmware; and

a nonce.

7. The method of claim 6 , wherein the firmware is authenticated using a trusted data store comprising a binary image of the firmware, and a certificate chain comprising a hardware digital certificate and the firmware measurement certificate.

8. The method of claim 1 , wherein the plurality of compute nodes is associated with a node hierarchy level, and wherein an authentication and verification manager for the node hierarchy level performs the authentication of the hardware architecture and the authentication of the firmware.

9. A system, comprising:

a processor; and

a memory component that stores instructions that cause the processor to:

authenticate a hardware architecture of each of a plurality of components of the compute nodes;

authenticate a firmware of each of the plurality of components; and

generate an authentication database comprising a plurality of authentication descriptions that are based on the authenticated hardware architecture and the authenticated firmware, wherein a policy for securing a specified subset of the compute nodes is implemented by using the authentication database.

10. The system of claim 9 , wherein the instructions cause the processor to implement the policy by (i) using an operation of an application program interface for authenticating compute node groups, and (ii) operating the authentication database.

11. The system of claim 9 , wherein one of the compute nodes comprises a controller that is connected to the plurality of components, and wherein the controller authenticates the hardware architecture of the plurality of components and authenticates the firmware of the plurality of components, wherein the controller compares the authenticated hardware architecture and the authenticated firmware with one or more previous authentications to detect changes to the hardware architecture and the firmware.

12. The system of claim 9 , wherein one of the compute nodes comprises a baseboard management controller and a computer processor, and wherein the baseboard management controller authenticates the hardware architecture of the computer processor and authenticates the firmware of the computer processor.

13. The system of claim 9 , wherein the instructions cause the processor to generate a firmware measurement certificate for each layer of firmware of the plurality of components, wherein:

a core root of trust generates the firmware measurement certificate for a first layer of the firmware;

the firmware measurement certificate for the first layer of the firmware specifies a trusted certification authority; and

authenticating the firmware is based on the firmware measurement certificate.

14. The system of claim 13 , wherein:

the firmware of the plurality of components operates the plurality of components;

the firmware measurement certificate comprises an attribute certificate; and

the firmware measurement certificate comprises:

a cumulative hash of the layer of firmware, wherein the cumulative hash comprises

a concatenation of:

a hash of the layer of firmware; and

a hash of each one or more lower layers of the firmware; and

a nonce.

15. The system of claim 14 , wherein the firmware is authenticated using a trusted data store comprising a binary image of the firmware, and a certificate chain comprising a hardware digital certificate and the firmware measurement certificate.

16. A non-transitory, computer-readable medium storing computer-executable instructions, which when executed, cause a computer to:

authenticate a hardware architecture of each of a plurality of components of the compute nodes;

authenticate a firmware of each of the plurality of components; and

generate an authentication database comprising a plurality of authentication descriptions that are based on the authenticated hardware architecture and the authenticated firmware, wherein a policy for securing a specified subset of the compute nodes is implemented by using the authentication database.

17. The non-transitory, computer-readable medium of claim 16 , wherein the computer-executable instructions cause the computer to implement the policy by (i) using an operation of an application program interface for authenticating compute node groups, and (ii) operating the authentication database.

18. The non-transitory, computer-readable medium of claim 16 , wherein one of the compute nodes comprises a controller that is connected to the plurality of components, and wherein the controller authenticates the hardware architecture of the plurality of components and authenticates the firmware of the plurality of components, wherein the controller compares the authenticated hardware architecture and the authenticated firmware with one or more previous authentications to detect changes to the hardware architecture and the firmware.

19. The non-transitory, computer-readable medium of claim 16 , wherein one of the compute nodes comprises a baseboard management controller and a computer processor, and wherein the baseboard management controller authenticates the hardware architecture of the computer processor and authenticates the firmware of the computer processor.

20. The non-transitory, computer-readable medium of claim 16 , wherein the computer-executable instructions cause the computer to generate a firmware measurement certificate for each layer of firmware of the plurality of components, wherein:

a core root of trust generates the firmware measurement certificate for a first layer of the firmware;

the firmware measurement certificate for the first layer of the firmware specifies a trusted certification authority; and

authenticating the firmware is based on the firmware measurement certificate.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2023
From: HEWLETT-PACKARD LIMITED
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 065120/0507 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2021
From: KRAUSE, MICHAEL R.; BENEDICT, MELVIN; LUCIANI, LUIS; LAFFEY, THOMAS; DASARI, SHIVA
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 056976/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2021
From: EDWARDS, NIGEL; JACQUIN, LUDOVIC EMMANUEL PAUL NOEL; KOULOURIS, THEOFRASTOS
To: HEWLET-PACKARD LIMITED
Reel/Frame 056976/0705 →
Continuity (1)
Related Publication 20220043914A1 · Feb 10, 2022