IP Library Granted Patent US 7,788,363
Granted Patent B2
US 7,788,363 · App. 12/218,414 · Granted Aug 31, 2010

Secure communication over virtual IPMB of a mainframe computing system

Assignee: Unisys Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,788,363
App. No.
12/218,414
Granted
Aug 31, 2010
Kind
B2
Abstract

In general, techniques for secure communicating over a virtual IPMB of a mainframe computing system are described herein. More specifically, the mainframe computing system comprises a plurality of independent computing cells communicatively coupled together by a network interconnect and that form a plurality of partitions. Each partition is a logical association of one or more of the cells to define a single execution environment. Each cell further executes a virtual intelligent platform management interface (IPMI) protocol to define and configure a respective logical intelligent platform management bus (IPMB) for each of the partitions. Each of the IPMBs logically interconnects with each of the other cells included within the same partition, and each is defined for communication of IMPI messages over the network interconnect. The cells securely communicate the IPMI messages between each of the one or more other cells of each partition via the respective logical IPMB of each partition.

Claims (51)

1. A method of communicating intelligent platform management interface data within a mainframe computing system, the method comprising:

forming a plurality of partitions within the mainframe computing system, wherein each partition is a logical association of one or more of a plurality of independent computing cells of the mainframe computing system communicatively coupled together by a network interconnect to define a single execution environment that includes the one or more logically associated cells, determining within each one of the plurality of partitions an associated partition identifier that uniquely identifies each of the plurality of partitions within the mainframe computing system;

executing a virtual intelligent platform management interface (IPMI) protocol to define and configure a respective logical intelligent platform management bus (IPMB) for each of the partitions, each of the IPMBs to logically interconnect each of the one or more plurality of cells included within the same one of the plurality of partitions, wherein configuring the logical IPMB within each of the plurality of partitions comprises assigning each of the logical IPMBs an associated bus number equal to the partition identifier associated with the partition in which the logical IPMB resides, wherein the bus number uniquely identifies each of the logical IPMBs within the mainframe computing system, and wherein each of the logical IPMBs are defined for communication of IPMB messages over the network interconnect; and

securely communicating the IPMI messages between each of the one or more cells of each partition via the respective logical IPMB of each partition.

2. The method of claim 1 , wherein securely communicating the IPMI messages between each of the one or more cells of each partition comprises forming an IPMI message addressed to an IPMB address in accordance with an IPMI protocol with an IPMI stack executing within one of the plurality of cells.

3. The method of claim 2 , wherein the IPMI stack comprises one of a system IPMI stack, a partition IPMI stack, and a resource IPMI stack.

4. The method of claim 3 , wherein securely communicating the IPMI messages further comprises:

securely communicating IPMI messages formed in accordance with the system IPMI stack via a first logical IPMB; and

securely communicating IPMI messages formed in accordance with the partition IPMI stack via a second logical IPMB.

5. The method of claim 4 , further comprising:

associating, with a system management software tool, a first set of users with the first logical IPMB;

associating, with a partition management software tool, a second set of users with the second logical IPMB; and

authenticating, with one or more of the system management software tool and the partition management software tool, a user as included within one or more of the first and second sets of users before allowing the user to initiate the secure communication of IPMI messages via the respective first logical IPMB, second logical IPMB, or both.

6. The method of claim 1 , wherein securely communicating the IPMI messages between each of the one or more cells of each partition further comprises:

accessing a mapping that stores associations between a bus number assigned to each logical IPMB of each of the partitions, an IPMB address assigned to each of the cells, and a media access control (MAC) address assigned to an Ethernet interface of each of the cells to determine an appropriate MAC address and bus number based on a given IPMB address;

encapsulating each of the IPMI messages directly within an Ethernet message that includes the appropriate MAC address and bus number; and

securely communicating the Ethernet messages via the logical IPMB associated with the bus number included within each of the Ethernet messages.

7. The method of claim 6 , further comprising determining an association stored to the mapping by:

transmitting a message with one of the cells requesting a response from the IPMB address assigned to one of the other cells;

receiving a response message from the IPMB address assigned to the other cell that indicates the MAC address assigned to an Ethernet interface of the other cell; and

determining a mapping between the MAC address assigned to the Ethernet interface of the other cell and the IPMB address assigned to the other cell.

8. The method of claim 7 , wherein securely communicating the IPMI messages between each of the one or more cells of each partition further comprises:

accessing a mapping that stores associations between a bus number assigned to each logical IPMB of each of the partitions, an IPMB address assigned to each of the cells, and an user datagram protocol (UDP) endpoint assigned to an interface of each of the cells to determine an appropriate UDP endpoint and bus number based on a given IPMB address;

encapsulating each of the IPMI messages within an universal datagram protocol/internet protocol (UDP/IP) message that includes the appropriate UDP endpoint and bus number; and

securely communicating the UDP/IP messages via the logical IPMB associated with the bus number included within each of the UDP/IP messages.

9. A mainframe computing system that communicates intelligent platform management interface (IPMI) data, the system comprising:

a network interconnect; and

a plurality of independent computing cells communicatively coupled together by the network interconnect, and that form a plurality of partitions, wherein each partition is a logical association of one or more of the plurality of cells to define a single execution environment that includes the one or more logically associated cells, wherein an associated partition identifier that uniquely identifies each of the plurality of partitions within the mainframe computing system is determined within each one of the plurality of partitions,

wherein each cell executes a virtual intelligent platform management interface (IPMI) protocol to define and configure a respective logical intelligent platform management bus (IPMB) for each of the partitions, assigning each of the logical IPMBs an associated bus number equal to the partition identifier associated with the partition in which the logical IPMB resides, wherein the bus number uniquely identifies each of the logical IPMBs within the mainframe computing system and wherein each of the IPMBs to logically interconnect each of the one or more plurality of cells included within the same one of the plurality of partitions, each of the logical IPMBs defined for communication of IMPI messages over the network interconnect, and

wherein the cells securely communicate the IPMI messages between each of the one or more other cells of each partition via the respective logical IPMB of each partition.

10. The system of claim 9 , wherein the cells securely communicate the IPMI messages between each of the one or more cells of each partition by forming an IPMI message addressed to an IPMB address in accordance with an IPMI protocol with an IPMI stack executing within one of the plurality of cells.

11. The system of claim 10 , wherein the IPMI stack comprises one of a system IPMI stack, a partition IPMI stack, and a resource IPMI stack.

12. The system of claim 11 , wherein the cells securely communicate the IPMI messages by:

securely communicating IPMI messages formed in accordance with the system IPMI stack via a first logical IPMB; and

securely communicating IPMI messages formed in accordance with the partition IPMI stack via a second logical IPMB.

13. The system of claim 12 , wherein each cell executes a system management software tool and a partition management software tool,

the system management software tool associates a first set of users with the first logical IPMB,

the partition management software tool associates a second set of users with the second logical IPMB, and

one or more of the system management software tool and the partition management software tool authenticate a user as included within one or more of the first and second sets of users before allowing the user to initiate the secure communication of IPMI messages via one or more of the respective first logical IPMB and second logical IPMB.

14. The system of claim 9 , wherein the cells further securely communicate the IPMI messages between each of the one or more cells of each partition by:

accessing a mapping within each of the cells that stores associations between a bus number assigned to each logical IPMB of each of the partitions, an IPMB address assigned to each of the cells, and a media access control (MAC) address assigned to an Ethernet interface included within each of the cells to determine an appropriate MAC address and bus number based on a given IPMB address;

encapsulating each of the IPMI messages directly within an Ethernet message that includes the appropriate MAC address and bus number; and

securely communicating the Ethernet messages via the logical IPMB associated with the bus number included within each of the Ethernet messages.

15. The system of claim 14 , wherein the cells further determine an association stored to the mapping by:

transmitting a message with one of the cells requesting a response from the IPMB address assigned to one of the other cells;

receiving a response message from the IPMB address assigned to the other cell that indicates the MAC address assigned to an Ethernet interface of the other cell; and

determining a mapping between the MAC address assigned to the Ethernet interface of the other cell and the IPMB address assigned to the other cell.

16. The system of claim 9 , wherein the cells further securely communicate the IPMI messages between each of the one or more cells of each partition by:

accessing a mapping that stores associations between a bus number assigned to each logical IPMB of each of the partitions, an IPMB address assigned to each of the cells, and an user datagram protocol (UDP) endpoint assigned to an interface of each of the cells to determine an appropriate UDP endpoint and bus number based on a given IPMB address;

encapsulating each of the IPMI messages within an universal datagram protocol/internet protocol (UDP/IP) message that includes the appropriate UDP endpoint and bus number; and

securely communicating the UDP/IP messages via the logical IPMB associated with the bus number included within each of the UDP/IP messages.

Assignments (13)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION (SUCCESSOR TO GENERAL ELECTRIC CAPITAL CORPORATION)
To: UNISYS CORPORATION
Reel/Frame 044416/0358 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2013
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL TRUSTEE
To: UNISYS CORPORATION
Reel/Frame 030082/0545 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2013
From: DEUTSCHE BANK TRUST COMPANY
To: UNISYS CORPORATION
Reel/Frame 030004/0619 →
SECURITY AGREEMENT Recorded Jun 27, 2011
From: UNISYS CORPORATION
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 026509/0001 →
SECURITY AGREEMENT Recorded Nov 2, 2010
From: UNISYS CORPORATION
To: DEUTSCHE BANK NATIONAL TRUST COMPANY
Reel/Frame 025227/0391 →
RELEASE BY SECURED PARTY Recorded Sep 14, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023263/0631 →
RELEASE BY SECURED PARTY Recorded Jul 31, 2009
From: CITIBANK, N.A.
To: UNISYS CORPORATION; UNISYS HOLDING CORPORATION
Reel/Frame 023312/0044 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Feb 10, 2009
From: UNISYS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 022237/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2008
From: SIEVERT, JAMES A.
To: UNISYS CORPORATION
Reel/Frame 021300/0068 →
Continuity (1)
Related Publication 20100017873A1 · Jan 21, 2010