US2017033970A9PendingUtilityA9

Migration of full-disk encrypted virtualized storage between blade servers

Assignee: INTEL CORPPriority: Dec 28, 2007Filed: Apr 28, 2015Published: Feb 2, 2017
Est. expiryDec 28, 2027(~1.4 yrs left)· nominal 20-yr term from priority
H04L 41/28H04L 41/00H04L 41/344H04L 9/0827H04L 9/0877G06F 11/203G06F 2221/2107G06F 21/80G06F 21/57H04L 63/061
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system and computer-readable storage medium with instructions to migrate full-disk encrypted virtual storage between blade servers. A key is obtained to perform an operation on a first blade server. The key is obtained from a virtual security hardware instance and provided to the first blade server via a secure out-of-band communication channel. The key is migrated from the first blade server to a second blade server. The key is used to perform hardware encryption of data stored on the first blade server. The data are migrated to the second blade server without decrypting the data at the first blade server, and the second blade server uses the key to access the data. Other embodiments are described and claimed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a plurality of blade servers; and   a chassis management module;   wherein each of the plurality of blade servers comprises a platform controller configured to manage an out-of-band interface between the chassis management module and a the plurality of blade servers.   
     
     
         2 . The system of  claim 1 , wherein the platform controller comprises a baseboard management controller. 
     
     
         3 . The system of  claim 1 , wherein each of the plurality of blade servers comprises a processor to execute an operating system, and the out-of-band interface is configured to operate independently of the execution of said operating system. 
     
     
         4 . The system of  claim 3 , wherein the out-of-band interface is configured to enable an administrator to manage the operation of the plurality of blade servers even in the absence of an operational operating system on one or more of the plurality of blade servers. 
     
     
         5 . The system of  claim 1 , further comprising an out-of-band communication channel, the out-of-band communication channel configured to enable the chassis management module to communicate directly with the platform controller. 
     
     
         6 . The system of  claim 1 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification. 
     
     
         7 . The system of  claim 1 , wherein the out-of-band interface is configured to cause software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware. 
     
     
         8 . The system of  claim 7 , wherein the out-of-band interface is configured to provide memory-mapped input/output registers in conformance with a trusted platform module interface specification. 
     
     
         9 . The system of  claim 7 , wherein said platform controller is further configured to send a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers. 
     
     
         10 . A method comprising,
 managing, with a platform controller of a system further comprising a plurality of blade servers and a chassis management module, an out-of-band interface between the chassis management module and the plurality of blade servers.   
     
     
         11 . The method of  claim 10 , wherein the platform controller comprises a baseboard management controller. 
     
     
         12 . The method of  claim 10 , wherein:
 each of the plurality of blade servers comprises a processor to execute an operating system;   the out-of-band interface is configured to operate independently of the execution of said operating system; and   the method further comprises managing the operation of the plurality of blade servers with the chassis management module even in the absence of an operational operating system on one of more of the plurality of blade servers.   
     
     
         13 . The method of  claim 10 , further comprising:
 with an out-of-band communication channel, enabling the chassis management module to communicate directly with the platform controller.   
     
     
         14 . The method of  claim 10 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification. 
     
     
         15 . The method of  claim 10 , further comprising, with the out-of-band interface:
 enabling software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware.   
     
     
         16 . The method of  claim 15 , wherein said enabling comprises providing, with the out-of-band interface, memory-mapped input/output registers in conformance with a trusted platform module interface specification. 
     
     
         17 . The method of  claim 15 , further comprising:
 transmitting, with said platform controller, a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers.   
     
     
         18 . At least one computer readable medium comprising computer readable instructions which when executed by a processor result in the performance of the following operations comprising:
 managing, with a platform controller of a system further comprising a plurality of blade servers and a chassis management module, an out-of-band interface between the chassis management module and the plurality of blade servers.   
     
     
         19 . The at least one computer readable medium of  claim 18 , wherein the platform controller comprises a baseboard management controller. 
     
     
         20 . The at least one computer readable medium of  claim 18 , wherein:
 each of the plurality of blade servers comprises a processor to execute an operating system;   the out-of-band interface is configured to operate independently of the execution of said operating system; and   said instructions when executed further result in the performance of the following operations comprising:
 managing the operation of the plurality of blade servers with the chassis management module even in the absence of an operational operating system on one of more of the plurality of blade servers. 
   
     
     
         21 . The at least one computer readable medium of  claim 18 , wherein said instructions when executed further result in the performance of the following operations comprising:
 with an out-of-band communication channel, enabling the chassis management module to communicate directly with the platform controller.   
     
     
         22 . The at least one computer readable medium of  claim 18 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification. 
     
     
         23 . The at least one computer readable medium of  claim 18 , wherein said instructions when executed further result in the performance of the following operations comprising:
 enabling, with the out-of-band interface, software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware.   
     
     
         24 . The at least one computer readable medium of  claim 23 , wherein said enabling comprises providing, with the out-of-band interface, memory-mapped input/output registers in conformance with a trusted platform module interface specification. 
     
     
         25 . The at least one computer readable medium of  claim 23 , wherein said instructions when executed further result in the performance of the following operations comprising:
 transmitting, with said platform controller, a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers.

Join the waitlist — get patent alerts

Track US2017033970A9 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.