AUTOMATIC MANAGEMENT NETWORK PROVISIONING
    11.
    发明申请

    公开(公告)号:US20180167271A1

    公开(公告)日:2018-06-14

    申请号:US15373885

    申请日:2016-12-09

    IPC分类号: H04L12/24 H04L12/18 H04L29/12

    摘要: According to one embodiment, a method for automatic management network provisioning includes: broadcasting a provisioning request to one or more devices; receiving at least one provisioning reply from the device(s); and broadcasting a provisioning configuration packet to device(s) from which a provisioning reply was received. In another embodiment, a method for peer-based automatic management network provisioning includes broadcasting network configuration information corresponding to a particular device to one or more other devices of a network environment; determining, after the broadcast, whether such network configuration information was modified; and requesting, from one or more of the other devices, the network configuration information corresponding to the particular device. The request is made in response to determining the particular device network configuration information was modified after broadcasting the network configuration information to the one or more other devices. Corresponding systems and computer program products are also disclosed.

    WORKLOAD ENCRYPTION KEY
    12.
    发明申请

    公开(公告)号:US20170359170A1

    公开(公告)日:2017-12-14

    申请号:US15178847

    申请日:2016-06-10

    IPC分类号: H04L9/08 H04L9/30 H04L9/14

    摘要: A workload server computing device receives a workload encryption key from a workload client computing device over a network. The workload encryption key is encrypted with a public encryption key of the workload server computing device. The workload server computing device decrypts the workload encryption key using a private encryption key of the workload server computing device corresponding to the public encryption key. The workload server computing device receives a workload from the workload client computing device over the network. The workload is encrypted with the workload encryption key. The workload server computing device decrypts the workload using the workload encryption key, and executes the decrypted workload for the workload client computing device.

    MICROCHECKPOINTING AS SECURITY BREACH DETECTION MEASURE

    公开(公告)号:US20170310701A1

    公开(公告)日:2017-10-26

    申请号:US15134327

    申请日:2016-04-20

    IPC分类号: H04L29/06

    摘要: A method includes: deploying at least one shadow system in association with each of one or more components of a network environment; periodically recording a state map of each active component of the network environment and a corresponding state map of the shadow system(S) associated therewith; periodically comparing the recorded state map of each active component with the corresponding recorded state map of the shadow system(s) associated therewith; determining whether a deviation exists with respect to the recorded state map of each active component and the corresponding recorded state map of the shadow system(s) associated therewith; determining whether the deviation is greater than a predetermined deviation threshold; and declaring a security breach regarding the active component(s) for which the deviation was determined to be greater than the predetermined deviation threshold. Corresponding systems and computer program products are also disclosed.

    ENABLING A MANAGEMENT FUNCTION IN RESPONSE TO WORKLOAD OWNERSHIP

    公开(公告)号:US20210124606A1

    公开(公告)日:2021-04-29

    申请号:US16664132

    申请日:2019-10-25

    IPC分类号: G06F9/46 G06F9/48

    摘要: An apparatus and a computer program product include program instructions configured to be executable by a processor to cause the processor to perform operations. The operations include managing workload instances running on a computing system that includes a plurality of compute nodes, wherein the workload instances include at least one workload instance owned by each of a plurality of users. The operations further include identifying, for each workload instance, which user among the plurality of users owns the workload instance and which compute node among the plurality of compute nodes is running the workload instance. Additionally, the operations further include enabling, for any given compute node among the plurality of compute nodes, a particular user among the plurality of users to perform a management function on the given compute node in response to all of the workloads running on the given compute node being owned by the particular user.

    Forming groups of nodes for assignment to a system management server

    公开(公告)号:US10992534B2

    公开(公告)日:2021-04-27

    申请号:US16567590

    申请日:2019-09-11

    IPC分类号: H04L12/24 H04L29/08

    摘要: An apparatus and a computer program product provide program instructions executable by a processor to perform operations. The operations include identifying a plurality of system management servers in a computer system and a node management capacity for each system management server, identifying a plurality of nodes in the computer system and a value of a node operating factor for each node, and dividing the plurality of nodes into groups, wherein each of the nodes in a group has the same value of the node operating factor. The operations further include assigning each one of the groups of nodes to one of the system management servers, wherein a sum of the nodes assigned to each system management server does not exceed the node management capacity of the system management server, and managing, for each system management server, the group of nodes that are assigned to the system management server.

    Automatic management network provisioning

    公开(公告)号:US10530643B2

    公开(公告)日:2020-01-07

    申请号:US15373885

    申请日:2016-12-09

    IPC分类号: H04L12/24 H04L29/12 H04L12/18

    摘要: According to one embodiment, a method for automatic management network provisioning includes: broadcasting a provisioning request to one or more devices; receiving at least one provisioning reply from the device(s); and broadcasting a provisioning configuration packet to device(s) from which a provisioning reply was received. In another embodiment, a method for peer-based automatic management network provisioning includes broadcasting network configuration information corresponding to a particular device to one or more other devices of a network environment; determining, after the broadcast, whether such network configuration information was modified; and requesting, from one or more of the other devices, the network configuration information corresponding to the particular device. The request is made in response to determining the particular device network configuration information was modified after broadcasting the network configuration information to the one or more other devices. Corresponding systems and computer program products are also disclosed.

    SYSTEM TO ENABLE SECURE BOOT FROM EXPIRED CERTIFICATE VIA DIGITAL SIGNATURE PROXY

    公开(公告)号:US20240330468A1

    公开(公告)日:2024-10-03

    申请号:US18129525

    申请日:2023-03-31

    IPC分类号: G06F21/57 H04L9/32

    摘要: A method for allowing a firmware update when a digital certificate for a firmware update image is expired includes initiating a firmware update of a computing device and determining, using a secure boot process, that a firmware update image has an expired digital certificate. The firmware update image is stored in nonvolatile memory accessible to a service processor and to a host processor of the computing device. The method includes determining that the firmware update image and an image of firmware with code of the secure boot process were digitally signed by a same entity and overriding the secure boot process to allow execution of the firmware update image in response to determining that the firmware update image and the image of the firmware with code of the secure boot process were digitally signed by a same entity.

    Configuring a replacement node using a configuration backup of a failed node being replaced

    公开(公告)号:US12047442B1

    公开(公告)日:2024-07-23

    申请号:US18487322

    申请日:2023-10-16

    IPC分类号: H04L67/104 H04L67/1042

    CPC分类号: H04L67/1048 H04L67/1042

    摘要: A replacement node replaces a failed node and a baseboard management controller (BMC) for the replacement node generates a nonce code that is accessible to an authenticated user. An edge management node receives the nonce code from the user and sends a maintenance token to a BMC of a peer node in an edge cluster, wherein the peer nodes BMCs within the cluster are in a BMC federation that included the failed node BMC and have access to a BMC configuration for the failed node. The management node sends the token and the nonce code to the replacement node BMC for authentication of the token. The peer node BMC sends the token received from the management node to the replacement node BMC for authentication of the peer node BMC. The authenticated peer node BMC may then deploy the BMC configuration to the replacement node BMC.