Migration of full-disk encrypted virtualized storage between blade servers
Abstract
A method, system and computer-readable storage medium with instructions to migrate full-disk encrypted virtual storage between blade servers. A key is obtained to perform an operation on a first blade server. The key is obtained from a virtual security hardware instance and provided to the first blade server via a secure out-of-band communication channel. The key is migrated from the first blade server to a second blade server. The key is used to perform hardware encryption of data stored on the first blade server. The data are migrated to the second blade server without decrypting the data at the first blade server, and the second blade server uses the key to access the data. Other embodiments are described and claimed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system, comprising:
a plurality of blade servers; and a chassis management module; wherein each of the plurality of blade servers comprises a platform controller configured to manage an out-of-band interface between the chassis management module and a the plurality of blade servers.
2 . The system of claim 1 , wherein the platform controller comprises a baseboard management controller.
3 . The system of claim 1 , wherein each of the plurality of blade servers comprises a processor to execute an operating system, and the out-of-band interface is configured to operate independently of the execution of said operating system.
4 . The system of claim 3 , wherein the out-of-band interface is configured to enable an administrator to manage the operation of the plurality of blade servers even in the absence of an operational operating system on one or more of the plurality of blade servers.
5 . The system of claim 1 , further comprising an out-of-band communication channel, the out-of-band communication channel configured to enable the chassis management module to communicate directly with the platform controller.
6 . The system of claim 1 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification.
7 . The system of claim 1 , wherein the out-of-band interface is configured to cause software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware.
8 . The system of claim 7 , wherein the out-of-band interface is configured to provide memory-mapped input/output registers in conformance with a trusted platform module interface specification.
9 . The system of claim 7 , wherein said platform controller is further configured to send a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers.
10 . A method comprising,
managing, with a platform controller of a system further comprising a plurality of blade servers and a chassis management module, an out-of-band interface between the chassis management module and the plurality of blade servers.
11 . The method of claim 10 , wherein the platform controller comprises a baseboard management controller.
12 . The method of claim 10 , wherein:
each of the plurality of blade servers comprises a processor to execute an operating system; the out-of-band interface is configured to operate independently of the execution of said operating system; and the method further comprises managing the operation of the plurality of blade servers with the chassis management module even in the absence of an operational operating system on one of more of the plurality of blade servers.
13 . The method of claim 10 , further comprising:
with an out-of-band communication channel, enabling the chassis management module to communicate directly with the platform controller.
14 . The method of claim 10 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification.
15 . The method of claim 10 , further comprising, with the out-of-band interface:
enabling software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware.
16 . The method of claim 15 , wherein said enabling comprises providing, with the out-of-band interface, memory-mapped input/output registers in conformance with a trusted platform module interface specification.
17 . The method of claim 15 , further comprising:
transmitting, with said platform controller, a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers.
18 . At least one computer readable medium comprising computer readable instructions which when executed by a processor result in the performance of the following operations comprising:
managing, with a platform controller of a system further comprising a plurality of blade servers and a chassis management module, an out-of-band interface between the chassis management module and the plurality of blade servers.
19 . The at least one computer readable medium of claim 18 , wherein the platform controller comprises a baseboard management controller.
20 . The at least one computer readable medium of claim 18 , wherein:
each of the plurality of blade servers comprises a processor to execute an operating system; the out-of-band interface is configured to operate independently of the execution of said operating system; and said instructions when executed further result in the performance of the following operations comprising:
managing the operation of the plurality of blade servers with the chassis management module even in the absence of an operational operating system on one of more of the plurality of blade servers.
21 . The at least one computer readable medium of claim 18 , wherein said instructions when executed further result in the performance of the following operations comprising:
with an out-of-band communication channel, enabling the chassis management module to communicate directly with the platform controller.
22 . The at least one computer readable medium of claim 18 , wherein the out-of-band interface is a trusted platform module interface in conformance with a trusted platform module interface specification.
23 . The at least one computer readable medium of claim 18 , wherein said instructions when executed further result in the performance of the following operations comprising:
enabling, with the out-of-band interface, software executing on a first blade server of the plurality of blade servers to function as though the first blade server was protected by security hardware.
24 . The at least one computer readable medium of claim 23 , wherein said enabling comprises providing, with the out-of-band interface, memory-mapped input/output registers in conformance with a trusted platform module interface specification.
25 . The at least one computer readable medium of claim 23 , wherein said instructions when executed further result in the performance of the following operations comprising:
transmitting, with said platform controller, a security command to said chassis management module via an out-of-band communication channel, the security command configured to cause the chassis management module to provide security functionality to the plurality of blade servers.Join the waitlist — get patent alerts
Track US2017033970A9 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.