Technologies for verifying authorized operation of servers

US2018262479A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018262479-A1
Application numberUS-201815976207-A
CountryUS
Kind codeA1
Filing dateMay 10, 2018
Priority dateDec 12, 2014
Publication dateSep 13, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Technologies for verifying authorized operation includes an administration server to query a dual-headed identification device of a server for identification data indicative of an identity of the server. The dual-headed identification device includes a wired communication circuit, a wireless communication circuit, and a memory having the identification data stored therein. The administration server further obtains the identification data from the dual-headed identification device of the server, determines a context of the server, and determines whether boot of the server is authorized based on the context of the server, the identification data of the server, and a security policy of the server.

First claim

Opening claim text (preview).

1 . A server for confirming authorized operation, the server comprising: a dual-headed identification device that includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; and a platform management module to (i) receive a query from an administration server, (ii) determine a context of the server, (iii) generate a response to the received query based on the determined context, and (iv) store the generated response to the memory of the dual-headed identification device for access by the administration server. 2 . The server of claim 1 , wherein to receive the query comprises to receive the query over the wireless communication circuit of the dual-headed identification device. 3 . The server of claim 2 , wherein the wireless communication circuit comprises a radio frequency identification circuit; and wherein to receive the query comprises to receive the query over the radio frequency identification circuit of the dual-headed identification device. 4 . The server of claim 2 , wherein to receive the query comprises to receive the query over an out-of-band communication channel between the administration server and the dual-headed identification device. 5 . The server of claim 1 , wherein to determine the context of the server comprises to determine a geographical location of the server. 6 . The server of claim 1 , wherein to generate the response to the received query comprises to attest to the integrity of at least one of the identification data or the context of the server. 7 . The server of claim 1 , further comprising a manageability engine to: read the memory of the dual-headed identification device to access the received query; and store the generated response to the memory of the dual-headed identification device, wherein to generate the response comprises generate the response by the manageability engine. 8 . The server of claim 7 , wherein the manageability engine comprises an out-of-band processor of the server. 9 . The server of claim 7 , wherein to read the memory comprises to read the memory via the wired communication circuit; and wherein to store the generated response comprises to store the generated response to the memory via the wired communication circuit. 10 . The server of claim 9 , wherein to read the memory comprises to read the memory over a dedicated communication bus between the dual-headed identification device and the manageability engine; and wherein the wired communication circuit is electrically coupled to the dedicated communication bus. 11 . The server of claim 7 , wherein the manageability engine is to perform at least one of an unlock, read, write, or lock operation on the memory of the dual-headed identification device based on credentials established at the time of provisioning of the dual-headed identification device. 12 . The server of claim 1 , wherein the platform management module is further to receive instructions based on a determination of the administration server regarding whether the server is authorized to operate based on the context and a security policy of the server. 13 . The server of claim 1 , wherein the platform management module is further to perform a security action in response to receipt of instructions that indicate the server is not authorized to operate based on the security policy. 14 . A method for confirming authorized operation of a server, the method comprising: receiving, by a dual-headed identification device of the server, a query from an administration server, wherein the dual-headed identification device includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; determining, by the server, a context of the server; generating, by the server, a response to the received query based on the determined context; and storing, by the server, the generated response to the memory of the dual-headed identification device for access by the administration server. 15 . The method of claim 14 , wherein receiving the query comprises receiving the query over the wireless communication circuit of the dual-headed identification device. 16 . The method of claim 14 , further comprising: reading, by a manageability engine of the server, the memory of the dual-headed identification device to access the received query; and storing, by the manageability engine, the generated response to the memory of the dual-headed identification device, wherein generating the response comprises generating the response by the manageability engine. 17 . The method of claim 16 , wherein reading the memory comprises reading the memory via the wired communication circuit; and wherein storing the generated response comprises storing the generated response to the memory via the wired communication circuit. 18 . The method of claim 17 , wherein reading the memory comprises reading the memory over a dedicated communication bus between the dual-headed identification device and the manageability engine; and wherein the wired communication circuit is electrically coupled to the dedicated communication bus. 19 . The method of claim 16 , further comprising performing, by the manageability engine of the server, at least one of an unlock, read, write, or lock operation on the memory of the dual-headed identification device based on credentials established at the time of provisioning of the dual-headed identification device. 20 . One or more computer-readable storage media comprising a plurality of instructions that in response to being executed cause a server to: receive, by a dual-headed identification device of the server, a query from an administration server, wherein the dual-headed identification device includes (i) a wired communication circuit, (ii) a wireless communication circuit, and (iii) a memory having stored therein identification data indicative of an identity of the server; determine a context of the server; generate a response to the received query based on the determined context; and store the generated response to the memory of the dual-headed identification device for access by the administration server. 21 . The one or more computer-readable storage media of claim 20 , wherein to receive the query comprises to receive the query over the wireless communication circuit of the dual-headed identification device. 22 . The one or more computer-readable storage media of claim 20 , further comprising a plurality of instructions that in response to being executed cause the server to: read, by a manageability engine of the server, the memory of the dual-headed identification device to access the received query; and store, by the manageability engine, the generated response to the memory of the dual-headed identification device, wherein to generate the response comprises to generate the response by the manageability engine. 23 . The one or more computer-readable storage media of claim 22 , wherein to read the memory comprises to read the memory via the wired communication circuit; and wherein to store the generated response comprises to store the generated response to the memory via the wired communication circuit. 24 . The one or more computer-readable storage media of claim 23 , wherein to read th

Assignees

Inventors

Classifications

  • when the policy decisions are valid for a limited amount of time · CPC title

  • Secure boot · CPC title

  • H04L63/107Primary

    wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • Location-sensitive, e.g. geographical location, GPS · CPC title

  • involving the use of external additional devices, e.g. dongles or smart cards · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018262479A1 cover?
Technologies for verifying authorized operation includes an administration server to query a dual-headed identification device of a server for identification data indicative of an identity of the server. The dual-headed identification device includes a wired communication circuit, a wireless communication circuit, and a memory having the identification data stored therein. The administration se…
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/107. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Sep 13 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).