MLchartDataset catalogue

Patent · US2010111309A1 · A1 · US

Encryption key management system and methods thereof

(11) Publication number
US2010111309A1
(21) Application number
12/262,962
(22) Filing date
2008-10-31
(30) Priority date
2008-10-31
(43) Publication date
2010-05-06
(51) IPC
G06F 9/24; G06F 9/54; H04L 9/06; H04L 9/08; H04L 9/32; G06F 21/00
(52) CPC
  • G06F Electric digital data processing: 21/575, 21/602
(73) Assignee
Dell Products LP
(72) Inventors
Mukund P. Khatri; Kevin T. Marks; Don H. Walker
(54) Title
Encryption key management system and methods thereof
(57) Abstract

During execution of BIOS at an information handling system, a processor communicates with the storage controller via a command line protocol (CLP) communications channel. Via the channel, the processor obtains identification information for storage devices associated with the storage controller. The processor communicates the identification information to a key management client, which obtains encryption keys based on the identification information from a key management server. The processor receives the encryption keys, and communicates them to the storage controller via the CLP communications channel. The CLP communications channel thus provides a convenient and flexible interface for communication of security information prior to execution of an operating system.

Full text
View on Google Patents

Claims (20)

  1. A method, comprising: receiving a first request for a first security parameter via a first command line protocol (CLP) communication; determining the first security parameter based on the first request; and communicating the first security parameter via a second CLP communication.
  2. The method of claim 1, wherein receiving the first request comprises: determining a first CLP entry point exit; and in response to determining the first CLP entry point exit, accessing a command buffer to determine the first request.
  3. The method of claim 1, wherein receiving the first request comprises receiving the first request in response to communicating a first memory address to the first storage controller, the first memory address associated with a first CLP entry point of an option read only memory (ROM).
  4. The method of claim 1, wherein the first security parameter comprises an encryption key associated with a storage device, the storage device associated with the first storage controller.
  5. The method of claim 4, wherein determining the first security parameter comprises: communicating a second request to a key management server, the second request based on the first request; and receiving the encryption key in response to the second request.
  6. The method of claim 5, wherein communicating the second request comprises communicating the second request to a baseboard management controller (BMC) of a first server.
  7. The method of claim 1, wherein the first security parameter comprises a plurality of encryption keys associated with a plurality of storage devices, each storage device associated with the first storage controller.
  8. The method of claim 1, further comprising: communicating a second request for authentication information to the first storage controller via a third CLP communication; receiving the authentication information in response to the second request; and communicating the first security parameter in response to authenticating the authentication information.
  9. The method of claim 1, further comprising: receiving a second request for authentication information from the first storage controller via the first CLP communications channel; and communicating the authentication information in response to the second request.
  10. The method of claim 1, further comprising: communicating a security request to the first storage controller via the first CLP communications channel, the security request comprising a request to change an encryption key.
  11. The method of claim 1, further comprising: communicating a security request to the first storage controller via the first CLP communications channel, the security request comprising a request to erase a portion of encrypted information stored at a storage device associated with the first storage controller.
  12. The method of claim 1, further comprising: receiving a second request from a second storage controller for a second security parameter via a third (CLP) communication; determining the second security parameter based on the second request; and communicating the second security parameter to the second storage controller via a fourth CLP communication.
  13. A method, comprising: receiving a first address at a storage controller, the first address associated with a first command line protocol (CLP) entry point of an option read only memory (ROM); and in response to receiving the first address, communicating a first request for a first encryption key associated with first encrypted information stored at a first storage device.
  14. The method of claim 13, further comprising: in response to receiving the first address, communicating a first request for a second encryption key associated with second encrypted information stored at the first storage device.
  15. The method of claim 13, further comprising: in response to receiving the first address, communicating a first request for a second encryption key associated with second encrypted information stored at a second storage device.
  16. The method of claim 13, further comprising: in response to receiving the first address, erasing a portion of encrypted information stored at storage device.
  17. The method of claim 13, further comprising: in response to receiving the first address, replacing a second encryption key with the first encryption key.
  18. The method of claim 13, further comprising: determining identification information for a storage device associated with the storage controller; and wherein the first request comprises the identification information.
  19. An information handling system, comprising: an option read-only memory (ROM) comprising a command line protocol (CLP) entry point; and a processor coupled to the CLP communications channel, the processor configured to: providing a first call to the CLP entry point in response to a boot request; receiving a first request for a first security parameter in response to providing the first call; determine the first security parameter based on the first request; and providing a second call to the CLP entry point in response to determining the first security parameter.
  20. The information handling system of claim 19, further comprising: a first buffer coupled to the processor, the first buffer configured to store commands provided by the processor associated with the first call; and a second buffer coupled to the processor, the second buffer configured to store information in response to the first call.

Description

This disclosure relates generally to information handling systems, and more particularly to transfer of security parameters for an information handling system.

As the value and use of information continues to increase, individuals and businesses seek additional ways to process and store information. One option is an information handling system. An information handling system generally processes, compiles, stores, and/or communicates information or data for business, personal, or other purposes. Because technology and information handling needs and requirements can vary between different applications, information handling systems can also vary regarding what information is handled, how the information is handled, how much information is processed, stored, or communicated, and how quickly and efficiently the information can be processed, stored, or communicated. The variations in information handling systems allow for information handling systems to be general or configured for a specific user or specific use such as financial transaction processing, airline reservations, enterprise data storage, or global communications. In addition, information handling systems can include a variety of hardware and software components that can be configured to process, store, and communicate information and can include one or more computer systems, data storage systems, and networking systems.

Security measures for information handling systems have continued to increase in importance. One such security measure is data encryption.

Citations (17)

  • US5953422A
  • US20010007131A1
  • US7751584B2
  • US7376968B2
  • US7552419B2
  • US7543150B2
  • US20070011491A1
  • US20070208883A1
  • US20070294520A1
  • US20080016143A1
  • US20080022134A1
  • US7949874B2
  • US20080133905A1
  • US7929706B2
  • US20090217374A1
  • US20090249053A1
  • US8127127B2
Record as JSON
{
  "publication_number": "US2010111309A1",
  "country": "US",
  "kind": "A1",
  "title": "Encryption key management system and methods thereof",
  "abstract": "During execution of BIOS at an information handling system, a processor communicates with the storage controller via a command line protocol (CLP) communications channel. Via the channel, the processor obtains identification information for storage devices associated with the storage controller. The processor communicates the identification information to a key management client, which obtains encryption keys based on the identification information from a key management server. The processor receives the encryption keys, and communicates them to the storage controller via the CLP communications channel. The CLP communications channel thus provides a convenient and flexible interface for communication of security information prior to execution of an operating system.",
  "claims": [
    "1. A method, comprising: receiving a first request for a first security parameter via a first command line protocol (CLP) communication; determining the first security parameter based on the first request; and communicating the first security parameter via a second CLP communication.",
    "2. The method of claim 1, wherein receiving the first request comprises: determining a first CLP entry point exit; and in response to determining the first CLP entry point exit, accessing a command buffer to determine the first request.",
    "3. The method of claim 1, wherein receiving the first request comprises receiving the first request in response to communicating a first memory address to the first storage controller, the first memory address associated with a first CLP entry point of an option read only memory (ROM).",
    "4. The method of claim 1, wherein the first security parameter comprises an encryption key associated with a storage device, the storage device associated with the first storage controller.",
    "5. The method of claim 4, wherein determining the first security parameter comprises: communicating a second request to a key management server, the second request based on the first request; and receiving the encryption key in response to the second request.",
    "6. The method of claim 5, wherein communicating the second request comprises communicating the second request to a baseboard management controller (BMC) of a first server.",
    "7. The method of claim 1, wherein the first security parameter comprises a plurality of encryption keys associated with a plurality of storage devices, each storage device associated with the first storage controller.",
    "8. The method of claim 1, further comprising: communicating a second request for authentication information to the first storage controller via a third CLP communication; receiving the authentication information in response to the second request; and communicating the first security parameter in response to authenticating the authentication information.",
    "9. The method of claim 1, further comprising: receiving a second request for authentication information from the first storage controller via the first CLP communications channel; and communicating the authentication information in response to the second request.",
    "10. The method of claim 1, further comprising: communicating a security request to the first storage controller via the first CLP communications channel, the security request comprising a request to change an encryption key.",
    "11. The method of claim 1, further comprising: communicating a security request to the first storage controller via the first CLP communications channel, the security request comprising a request to erase a portion of encrypted information stored at a storage device associated with the first storage controller.",
    "12. The method of claim 1, further comprising: receiving a second request from a second storage controller for a second security parameter via a third (CLP) communication; determining the second security parameter based on the second request; and communicating the second security parameter to the second storage controller via a fourth CLP communication.",
    "13. A method, comprising: receiving a first address at a storage controller, the first address associated with a first command line protocol (CLP) entry point of an option read only memory (ROM); and in response to receiving the first address, communicating a first request for a first encryption key associated with first encrypted information stored at a first storage device.",
    "14. The method of claim 13, further comprising: in response to receiving the first address, communicating a first request for a second encryption key associated with second encrypted information stored at the first storage device.",
    "15. The method of claim 13, further comprising: in response to receiving the first address, communicating a first request for a second encryption key associated with second encrypted information stored at a second storage device.",
    "16. The method of claim 13, further comprising: in response to receiving the first address, erasing a portion of encrypted information stored at storage device.",
    "17. The method of claim 13, further comprising: in response to receiving the first address, replacing a second encryption key with the first encryption key.",
    "18. The method of claim 13, further comprising: determining identification information for a storage device associated with the storage controller; and wherein the first request comprises the identification information.",
    "19. An information handling system, comprising: an option read-only memory (ROM) comprising a command line protocol (CLP) entry point; and a processor coupled to the CLP communications channel, the processor configured to: providing a first call to the CLP entry point in response to a boot request; receiving a first request for a first security parameter in response to providing the first call; determine the first security parameter based on the first request; and providing a second call to the CLP entry point in response to determining the first security parameter.",
    "20. The information handling system of claim 19, further comprising: a first buffer coupled to the processor, the first buffer configured to store commands provided by the processor associated with the first call; and a second buffer coupled to the processor, the second buffer configured to store information in response to the first call."
  ],
  "description_excerpt": "This disclosure relates generally to information handling systems, and more particularly to transfer of security parameters for an information handling system.\n\nAs the value and use of information continues to increase, individuals and businesses seek additional ways to process and store information. One option is an information handling system. An information handling system generally processes, compiles, stores, and/or communicates information or data for business, personal, or other purposes. Because technology and information handling needs and requirements can vary between different applications, information handling systems can also vary regarding what information is handled, how the information is handled, how much information is processed, stored, or communicated, and how quickly and efficiently the information can be processed, stored, or communicated. The variations in information handling systems allow for information handling systems to be general or configured for a specific user or specific use such as financial transaction processing, airline reservations, enterprise data storage, or global communications. In addition, information handling systems can include a variety of hardware and software components that can be configured to process, store, and communicate information and can include one or more computer systems, data storage systems, and networking systems.\n\nSecurity measures for information handling systems have continued to increase in importance. One such security measure is data encryption.",
  "cpc": [
    "G06F 21/575",
    "G06F 21/602"
  ],
  "ipc": [
    "G06F 9/24",
    "G06F 9/54",
    "H04L 9/06",
    "H04L 9/08",
    "H04L 9/32",
    "G06F 21/00"
  ],
  "assignees": [
    "Dell Products LP"
  ],
  "inventors": [
    "Mukund P. Khatri",
    "Kevin T. Marks",
    "Don H. Walker"
  ],
  "filing_date": "2008-10-31",
  "publication_date": "2010-05-06",
  "priority_date": "2008-10-31",
  "application_number": "US-26296208-A",
  "family_id": "42131421",
  "cited_by_count": 39,
  "citations": [
    "US5953422A",
    "US20010007131A1",
    "US7751584B2",
    "US7376968B2",
    "US7552419B2",
    "US7543150B2",
    "US20070011491A1",
    "US20070208883A1",
    "US20070294520A1",
    "US20080016143A1",
    "US20080022134A1",
    "US7949874B2",
    "US20080133905A1",
    "US7929706B2",
    "US20090217374A1",
    "US20090249053A1",
    "US8127127B2"
  ]
}

Record 5,492 of 8,000 in Patents full text (MLC-0201). Request the full dataset.