System and method for supporting at least one of subnet management packet (smp) firewall restrictions and traffic protection in a middleware machine environment
8 claims: 5 independent, 3 dependent
- 11つ以上のマイクロプロセッサで動作するミドルウェアマシン環境におけるサブネットマネジメントパケット(SMP)のファイアウォール制限を提供するための方法であって、 インフィニバンド(IB)ファブリックに接続するホストチャンネルアダプタ(HCA)に安全なファームウェアの実装を提供することを含み、前記HCAは、ホストに関連付けられており、さらに、 前記安全なファームウェアの実装を介して少なくとも1つのSMPを受信することを含み、前記少なくとも1つのSMPは、前記ホストから受信されるか、前記ホストに宛てられ、さらに、 前記安全なファームウェアの実装を介して、前記ホストが前記少なくとも1つのSMPを前記IBファブリックに送信すること、または前記ホストに宛てられた前記少なくとも1つのSMPを受信することを防止することを含 み 、 さらに、 前記安全なファームウェアの実装がプロキシ機能を含むのを可能にすることを含み、前記プロキシ機能は、ローカルの帯域外のインタフェースを通して、ホストソフトウェアと通信できる、 方法。
- 2SMPのファイアウォールコンポーネントを前記安全なファームウェアの実装に含めることをさらに含む、請求項1に記載の方法。
- 3前記SMPのファイアウォールコンポーネントが1つ以上のSMPベースの動作を防止するのを可能にすることをさらに含む、請求項2に記載の方法。
- 4前記SMPのファイアウォールコンポーネントが前記ホス トソ フトウェアとサブネットマネージャとの間のSMPベースの通信を防止するのを可能にすることをさらに含む、請求項2または3に記載の方法。
- 5前記SMPのファイアウォールコンポーネントの一部として特別なルールを実装することをさらに含む、請求項2~4のいずれか1項に記載の方法。
- 6サブネットマネージャが前記プロキシ機能を介して前記ホストソフトウェアにSMPを送信するのを可能にすることをさらに含む、請求項1~5のいずれか1項に記載の方法。
- 71つ以上のマイクロプロセッサで動作するミドルウェアマシン環境におけるサブネットマネジメントパケット(SMP)のファイアウォール制限を提供するためのシステムであって、 ホストチャンネルアダプタ(HCA)に関連付けられている1つ以上のホストと、 前記HCAの安全なファームウェアの実装とを備え、 前記安全なファームウェアの実装は、前記ホストからの、または前記ホストに宛てられた少なくとも1つのSMPを受信するように動作し、前記ホストが前記少なくとも1つのSMPを送信または受信することを防止するように動作 し、 前記安全なファームウェアの実装は、プロキシ機能を含み、前記プロキシ機能は、ローカルの帯域外のインタフェースを通して、ホストソフトウェアと通信できる、 システム。
- 8請求項1~ 6 のいずれか1項に記載の方法を実行するための、1つ以上のプロセッサによって実行するための命令を備える、コンピュータプログラム。
Independent claims8
86 paragraphs, as filed
Copyright notice Some of the disclosures in this patent document are subject to copyright protection. The copyright holder will not object to any reproduction of this patent document or disclosure by any person as long as it is in the patent file or record of the Patent and Trademark Office, but otherwise in all cases all works. Hold the right.
Field of Invention: The present invention relates generally to software such as computer systems and middleware, and particularly to supporting middleware machine environments.
background: Interconnect networks play a beneficial role in next-generation supercomputers, clusters, and data centers. High-performance network technologies such as InfiniBand (IB) technology are a unique or low-performance solution in high-performance computing domains where high bandwidth and low latency are important requirements. It is replacing. For example, the IB equipment is the Roadrunner at the Los Alamos National Laboratory, the Ranger at the Texas Advanced Computing Center, and the Juropa at the Forschungszcntrum Juelich. Used in supercomputers such as JuRoPa).
The IB was first standardized in October 2000 by integrating two older technologies called Future I / O and Next Generation I / O. High Performance Computing :: HPC as a solution for building large, scalable computer clusters due to its low latency, high bandwidth, and efficient use of host-side process resources. ) It is being accepted by the community. The de facto system software for IB is OpenFabrics Eenterprise Distribution (OFED), which is developed by dedicated professionals and maintained by the OpenFabrics Alliance. OFED is open source and can be used with both GNU / Linux (Linux) (registered trademark) and Microsoft Windows (Microsoft Windows) (registered trademark).
<p num="0005"> wrap up: This specification describes a system and a method for introducing a firewall limitation of a subnet management packet (SMP) in a middleware machine environment. A secure firmware implementation can be provided by a Host Channel Adapter (HCA), which is associated with a host in a middleware machine environment. A secure firmware implementation works to receive at least one SMP from or addressed to the host and prevents the host from sending or receiving at least one SMP. In addition, secure firmware implementations may include proxy capabilities that can communicate with external management components on behalf of the host.</p><p num="0006"> It also describes systems and methods for providing protection for switch-based subnet management packet (SMP) traffic in a middleware machine environment. The middleware machine environment includes a network switch that operates to receive at least one SMP addressed to a Subnet Management Agent (SMA) component. The network switch can check if at least one SMP contains the correct management key, and if at least one SMP does not contain the correct management key, at least one SMP will be forwarded to the addressed SMA. To prevent that. In addition, network switches can identify different management keys for each external port and enforce separate restrictions on ingress and egress SMP traffic on their own external ports.</p>
<figref num="1">It is a figure which shows that it supports the management key protection model in the platform of the middleware machine which follows one Embodiment of this invention.</figref><figref num="2">It is a figure which shows that the firewall limitation of SMP is brought about in the middleware machine environment according to one Embodiment of this invention.</figref><figref num="3">An example of a flowchart for providing firewall limitation of SMP in a middleware machine environment according to an embodiment of the present invention is shown.</figref><figref num="4">It is a figure which shows that the traffic of the switch-based SMP is protected in the middleware machine environment according to one embodiment of the present invention.</figref><figref num="5">An example of a flowchart for providing protection of switch-based SMP traffic in a middleware machine environment according to an embodiment of the present invention is shown.</figref>
Detailed description: This specification describes a system and a method for providing a middleware machine or a similar platform. According to one embodiment of the invention, the system is equipped with high performance hardware such as 64-bit processor technology, high performance large memory, and redundant Infiniband and Ethernet (registered trademark) networking, and the Web Logic Suite. Provide a complete Java® EE application server complex by providing a combination with an application server or middleware environment such as. This complex is a massively parallel in-memory grid. Includes grid), can be provisioned quickly, and can be scaled on demand. According to one embodiment, the system provides a full, one-half, or one-quarter rack or other configuration that provides an application server grid, storage area network, and InfiniBand (IB) network. Can be prepared as. Middleware machine software can be application servers, middleware, or, for example, Weblogic (WebLogic) servers, Jrockit or Hostpot JVM, Oracle Linux (Linux)® or Solaris (Solaris). , And can provide execution of other functions such as Oracle VM. According to one embodiment, the system may include multiple computer nodes, IB switch gateways, and storage nodes or units that communicate with each other over an IB network. When implemented as a rack configuration, its unused portion may remain empty or may be occupied by a filler.
According to an embodiment of the invention referred to herein as "Sun Oracle Exalogic" or "Exalogic", the System is an Oracle Middleware SW suite. Or an easy-to-deploy solution for hosting middleware or application server software such as Weblogic. As described herein, according to one embodiment, the system is one or more. A "grid in a box" with servers, storage units, an IB fabric for storage networking, and all other components required to host middleware applications. For example, Real Application Clusters and Exalogic open. Leveraging a large parallel grid architecture with storage) can provide significant performance for all types of middleware applications. The system provides improved performance along with linear I / O scalability, is easy to use and manage, and provides mission-critical availability and reliability.
M_ key protection model FIG. 1 is a diagram showing support for a management key protection model in a platform of a middleware machine according to an embodiment of the present invention. As shown in Figure 1, a management key such as the M_key 102 can be used to protect the IB fabric (or IB subnet) 100. The value of the M_key 102 may only be known to the Fabric Administrator 110, which is the IB Subnet / Fabric 100, Switch 103-104, and the designated Subnet Manager (SM) Node 101. Allows admin access to and. The integrity of the M_key 102 includes, for example, the physical access protection of switches 103-104 on the IB subnet / fabric 100 in the data center and the integrity of the fabric-level administrator password used by the fabric administrator 110. Depends on.
In IB Fabric 100, the secure HCA firmware implementation in HCA121-124 allows it to retain a variety of well-defined fabric node types and identities. Each of HCA121-124 can implement Subnet Management Agent (SMA) components 131-134, and each SMA component can be associated with M_key 141-144. In addition, the connected switches A103 and B104 may be controlled by the fabric administrator 110. Therefore, any rogue SMA implementation 131-134 may not compromise the M_key 102 value defined by the Fabric Administrator 110 and used on the IB subnet / Fabric 100.
Yet another description of the various embodiments using secure HCA firmware implementations on middleware machine platforms is the Secure Subnet Management Agent (SMA) in Infiniband (IB) Networks, filed June 4, 2012. ) Is provided in US Patent Application No. 13 / 487,973, entitled "Systems and Methods for Providing ), the application of which is incorporated herein by reference.
In addition, Fabric Administer 110 can ensure that the new M_key value 102 for IB Subnet / Fabric 100 is installed out-of-band on switches 103-104 (also for the corresponding Subnet Manager instance 101). .. In addition, the fabric admin straighter 110 ensures that there is an infinite lease time for the M_key 102 on switches 103-104. Therefore, host-based software 161-164, for example, a host-based subnet manager for different hosts 111-114 (including operating systems 151-154), controls any switch 103-104 on the IB subnet / fabric 100. I can't hijack.
According to one embodiment of the invention, a single M_key 102 value (or a single set of M_key values) is an IB subnet / based on the access restrictions defined in the IB specification. Can be used for various nodes in Fabric 100. The exact value of the current M_key 102 may need to be determined before reading or updating the M_key 102. This is because secure HCA firmware can ensure that the "read-protected" M_ key assigned to the local HCA121-124 is not visible to the localhost-based software.
In addition, if the current M_ key value for the HCA port is defined at run-time, local software 161-164 on different hosts 111-114 sets up its own M_ key value. By doing so, you may be able to hijack the HCA port. Host-local software 161-164 also manages the HCA port for the specified subnet manager 101, for example, before the specified subnet manager 101 sets up any M_key 102 for the HCA 121-124. Make it impossible.
According to one embodiment of the invention, the designated subnet manager 101 can ignore any HCA with an unknown M_ key value and leave the corresponding link uninitialized. The only effect on the M_ key of the hijacked HCA port is that the HCA port can become inoperable and the designated subnet manager 101 will be in normal communication, ie SMP / VL15. It can prevent host-based software from communicating through this HCA port, which uses non-based communication.
In addition, if host software 111-114 compromises the M_ key value of the local HCA, the host software in question will transfer the HCA port to the activated local identifier (LID) and partition membership ( It can be put into an operating state with a partition membership). In such a case, if the switch port of switch 103-104 connecting to HCA121-124 is controlled by a different M_key value unknown to the host software 111-114 that compromised the local HCA M_key value. If so, then the offending host software 111-114 may not be able to bring the link into full operating condition to allow normal data traffic.
According to one embodiment of the invention, IB Fabric 100 prevents SMP of direct routes between various hosts 111-114 to avoid various potentially threatening situations. it can. In some situations, the host, eg host 111, routes directly to hijack the M_ key on the remote host, eg, 112 HCA port, after the remote host 112 and / or the remote HCA122 is reset. SMP can be used. This makes the remote HCA122 port inaccessible from the SM101, thereby preventing the remote host 112 from joining normal IB communication, a denial of service (Dos) attack. In another situation, when two hosts, eg hosts 111 and 114, are compromised by a hacker, co-management in IB Fabric 100, which relies on the SMP of the direct route, is performed by the two compromised hosts. It may be possible to exchange information using the SMP of the direct route.
IB Fabric 100 may support co-management to exchange information between different hosts 111-114 without relying on the SMP of the direct route. For example, an admin streamer for a host can access a shared web page on the Internet instead of relying on a direct route SMP in IB Fabric 100. From a fabric security standpoint, leaving the SMP directly rooted as a security hole on the IB fabric is worse than allowing both host admins to access shared web pages on the Internet. Can be considered.
According to one embodiment of the invention, the HCA port gives the M_key 102 a finite lease time, for example, due to the high effectiveness of the subnet manager 101 for maintaining the lease term of the M_key 102. Can be set up. Therefore, the M_key 102 can expire without the associated link going down. As a result, the state of HCA121-124, for example partition membership, can be updated while the link is still in active mode and the LID route for the port involved is still operational. The IB Fabric 100, which is then unprotected by the M_ key, can inadvertently allow normal IB traffic between the hijacked host and the host on another partition.
In addition, if the M_key 102 expires before the link goes down, both the local HCA, eg HCA121, and any remote HCA, HCA124, can be hijacked and partition membership can be modified. If the associated switch port, for example Switch 103-104, is not set up to perform partition enforcement, traffic with unrequired partition membership will be any other in the fabric. Can reach the node of.
In addition, Subnet Manager 101 within IB Fabric 100 accurately monitors and controls IB Fabric 100 and other IB Fabric 100, depending on the specified virtual lane (VL), eg VL15 buffering. You can negotiate with the subnet manager. Since the buffering of VL15 in IB Fabric 100 is a shared resource, uncontrolled use of SMP from any host can indicate a DoS attack. This can affect the behavior of Subnet Manager 101. This is because the protection of the M_ key in IB Fabric 100 can prevent the host from changing the state of any SMA on any node. Therefore, it is necessary to protect SMP traffic in IB Fabric 100.
According to one embodiment of the invention, the M_key 102 may be created and managed by the fabric administrator 110 and stored in the secure memory of switches A103 and B104 and / or HCA121-124. The microprocessor of HCA121-124 or switches A103 and B104 can access memory to read M_key 102 or write M_key 102 to memory.
SMP firewall limits According to one embodiment of the invention, secure HCA firmware can use SMP firewall restrictions to prevent host-based software from hijacking either local or remote HCA ports. SMP firewall restrictions can prevent the host software from sending SMP requests to the fabric, or reject any SMP that would otherwise be forwarded to the host software.
FIG. 2 shows that the firewall limitation of SMP in the middleware machine environment according to the embodiment of the present invention is brought about. As shown in FIG. 2, the middleware machine environment 200 may include one or more hosts 203-204 and an IB fabric 210 associated with subnet manager 201. Each of hosts 203-204 connects to IB fabric 210 via HCA211-212, which implements HCA firmware 215-216.
HCA Firmware 215-216 effectively prevents any SMP-based denial of service (DoS) attacks, such as targeting the operation of Subnet Manager 201, and is SMP-based with reliable nodes in Fabric 200. May include SMP firewall components 213-214 that can allow the legal use of these tools. HCA's SMP firewall component 213-214 prevents host stack software 205-206 from sending SMP 220 to IB Fabric 210. In addition, the secure HCA firmware 215 is otherwise transferred to the host software 205 to prevent the information on the remote node, eg, host 204, from being improperly provided to the local host software, eg, host software 205. SMP230 received from IB Fabric 210 that will be rejected can be rejected.
In addition, SMP's firewall components 213-214 perform various SMP-based behaviors with host stack software 205-206, for example, by monitoring the identification of locally connected switch ports when subnet manager 201 does not work. Can be prevented. In addition, any SMP-based communication from subnet manager 201 with host stack software 205-206 or other legitimate components in the fabric may be prevented.
According to one embodiment of the invention, secure HCA firmware 215-216 implements certain rules as part of SMP firewall components 213-214, and legitimate behavior is due to host stack software 205-206. You can be sure that it will be possible. These rules allow certain SMP-based request and response types to be sent and received at tightly controlled rates. In addition, these rules can define source and destination limits for both direct and LID SMPs.
In addition, these rules can allow hypervisor instances that currently control the physical hosts 203 and 204 associated with HCA instances 211-1212, or SMP-based authentication for OS 207 and 208. Yet another description of the various embodiments of authentication of the discovered components on the platform of the middleware machine identifies the components found in the Infiniband (IB) network, filed June 4, 2012. Provided in US Patent Application No. 13 / 488,040 entitled "Systems and Methods for Certification", the application of which is incorporated herein by reference.
According to one embodiment of the invention, secure HCA firmware 215 implements proxy functions 217-218 to ensure that legitimate operation is enabled for host stack software 205-206. be able to. External management components such as Subnet Manager 201 can send the vendor's SMP221 to host stack software 205-206 via proxy features 217-218. Host stack software 205-206 can communicate with proxy function 217-218 via the local out-of-band interface 223-224 between HCA firmware 215-216 and host stack software 205-206. And this proxy function 217-218 is responsible for implementing certain legitimate behavior on behalf of host stack software 205-206, and host stack software 205 on behalf of remote fabric management components such as subnet manager 201. Can be responsible for communicating with -206.
Secure HCA firmware 215-216 can protect the IB fabric 210 from searching for unauthenticated configuration information, for example, the local host software has a globally unique identifier (GUID), LID, and remote IB. Prevents monitoring information about remote IB nodes, such as partition membership, which can potentially be used as the basis for DOS attacks on nodes). The secure HCA firmware 215-216 also limits the ability of the active subnet manager back to monitor information about remote nodes that can be used to enable successful data communication to remote nodes. Allows the local HCA211-212 to adequately protect the configuration of its local M_key 202 from the access of the local host.
In addition, secure HCA firmware 215-216 can prevent (or may not work) legacy SMP-based diagnostic and monitoring tools from being used on unreliable hosts. This is because a secure HCA can block any SMP operation sent by an unreliable host. Also, the M_ key scheme (scheme) can be used with full read protection, which can limit the ability to use legacy tools depending on SMP.
In addition, secure HCA firmware 215 can protect IB Fabric 200 from unauthenticated SMP-based communications between unreliable hosts. Secure HCA firmware 215 can protect the IB fabric from unauthenticated SMP traffic that is vulnerable to DoS attacks targeting the operation of SM201, for example. Different admission control policies can limit SMP injection rates for hosts 203-204 to acceptable levels. Instead, to further prevent DOS attacks, for example, taking advantage of the SMP blocking feature of secure HCA firmware, a single subnet configuration blocks all SMP operation from unreliable hosts. It is also good.
In addition, secure HCA firmware 215 can protect IB Fabric 210 from DoS attacks targeting subnet admin striker (SA) access. Secure HCA firmware 215 can guarantee QoS / fairness and scalability to access the SA. Also, to prevent DoS, SM201 may be allowed to shut down the HCA port that is causing the "overload" of SA requests, for example, exceeding the request speed threshold at certain time intervals.
FIG. 3 shows an example of a flowchart for providing SMP firewall restrictions in a middleware machine environment according to an embodiment of the present invention. As shown in Figure 3, in step 301, a secure firmware implementation can be provided with a host channel adapter (HCA) that connects to the InfiniBand (IB) fabric, and the HCA is associated with one host. Then, in step 302, the secure firmware implementation can receive at least one SMP, which is either received from or addressed to the host. Further, in step 303, the secure firmware implementation prevents the host from sending at least one SMP to the IB fabric or receiving at least one SMP addressed to the host.
Switch-based proxy M_key protection According to one embodiment of the invention, the SMP M_key check is performed on the intermediate switch node in the IB fabric to set the M_key on the local switch to a remote HCA port that does not allow the M_key to be set up. You can be sure that you can protect it.
FIG. 4 shows that it provides protection for switch-based SMP traffic in a middleware machine environment according to an embodiment of the present invention. As shown in FIG. 4, the middleware machine environment 400 may include an IB switch 401 that connects to the host 403 via the HCA 402. Host 403 may include host stack software 405 running on operating system 407. The IB switch 401 may include one or more switch ports 411-416, where each switch port can be used to connect to a separate node, or entity in the IB fabric 400, eg, switch port 411. Connected to HCA402.
Subnet Management Agent (SMA) component 406 is implemented in HCA402 firmware 404 and can communicate with other nodes in IB Fabric 400 via switch port 411. Also, the designated subnet manager 408 in IB Fabric 400 is specific for both sending direct route SMP requests to any SMA406 and receiving direct route SMP responses from SMA406. A switch port (for example, port 411) can be used.
Switch 401 can prevent unintended SMP traffic occurring in IB Fabric 400 without relying on the requirement that all HCA have reliable firmware with SMP control. For example, switch 401 can eliminate direct route SMP traffic that does not match the fabric policy for IB fabric 400.
Switch 401 can use a filtering scheme to prevent the remote HCA port 402 from being hijacked by an intruder. The removal method can be based on identifying any direct route SMP request that targets to set the attributes of SMA406. In addition, the removal method can perform the same M_ key check for all direct route SMP requests, independent of the destination, and the direct route independent of which destination the SMP is targeting. SMP request may be required to include the exact M_key 409 for local switch 401.
A single M_key 409 can be used with the IB fabric 400, which includes a switch 401 and an HCA port 402 that connects directly to the switch 401. If the host stack software 405 can compromise the M_key 419 that protects the local HCA402, the host stack software 405 can also compromise the M_key 409 that protects the local switch 401. This is because all SMP traffic in IB Fabric 400 includes the M_ key 409 on the local switch.
According to one embodiment of the invention, an implementation of switch 401 can identify an optional M_key value for each external port, eg, M_key 421-426 for external ports 411-416. .. In addition, the implementation of switch 401 is such that any SMP sent from, for example, switch port 411, and any SMP received from this port are all identified for switch port 411. You can be sure that you have an M_ key value that matches key 421. In addition, the network switch 401 can enforce separate restrictions on what the SMP 420 sends on the external port 414 and what the SMP 410 receives on the external port 414.
By using this mechanism, if the exact local M_ key associated with the switch port is identified, the legitimate subnet manager 408 will have all potentially unreliable remote HCA ports or other You can ensure that potentially unreliable remote ports can only be allowed to send SMPs. Also, attempts to access a remote port may require having a defined M_ key for subnet manager 408 for that port, independent of whether the remote port's M_ key was hijacked. .. In addition, this mechanism defines how quickly remote ports can generate SMP to prevent or reduce the chances of SMP-based DoS attacks from unreliable ports in the fabric. The speed can also be specified.
An additional description of various embodiments using SMP removal on the platform of middleware machines was filed on June 2, 2004 and published on July 8, 2008, "To Authenticate Nodes in Communication Networks. Provided in US Pat. No. 7,398,394 entitled "Systems and Methods of the United States", the application of which is incorporated herein by reference.
According to one embodiment of the invention, the removal scheme is an illegal host-host-based direct route based on what the switch port reveals as "reliable" or "unreliable." SMP traffic can be prevented. Determining whether a switch port, or an entity that connects to a switch port, is reliable can be based on explicit policy input to the local switch 401 or automatic authentication of the remote port.
As shown in FIG. 4, switch ports 411, 413-414, and 416 are reliable switch ports, while switch ports 412 and 415 are unreliable. The removal method can only allow SMP requests to be sent from a reliable port (exit from the switch) and SMP responses to be received from a reliable port (entry to the switch). .. In addition, a single SMA request entering the subnet from a trusted port in the first location may be allowed to exit towards the unreliable port. Therefore, the removal method can be done independently of any current M_ key setting and can be used in conjunction with the M_ key-based removal method described above.
According to one embodiment of the invention, the ability to use a single M_key 409, or a single set of M_keys, means that all nodes in the IB fabric 400 are trusted through the IB subnet / fabric 400. Depends on whether or not the M_ key in use is exposed to any entity that does not have the required privileges. The requirement for subnet manager 408 to include the current M_key in a request allows subnet manager 408 to guarantee that the target and any intermediate agent cannot compromise the integrity of the M_key. That is. In one example, such total reliability can be established before including the current M_ key in any SMP. Therefore, the fabric configuration is based on any M_ key, instead of assuming that all nodes in the IB fabric, including HCA, are entirely reliable for all SMA instances. It may be required to be authenticated (or revealed) as reliable before any communication can occur.
According to one embodiment of the invention, a mechanism for transmitting and receiving vendor-based SMPs via the switch management interface may be provided. Such a mechanism allows the switch built-in authentication mechanism to operate as part of the switch's local software, thereby working with the built-in subnet manager and built-in switch driver and SMA.
FIG. 5 shows an example of a flowchart for protecting switch-based SMP traffic in a middleware machine environment according to an embodiment of the present invention. As shown in Figure 5, at step 501, the network switch can receive one or more SMPs destined for the Subnet Management Agent (SMA). Then, in step 502, the network switch can check if one or more SMPs contain the correct management key. Further, in step 503, the network switch can prevent one or more SMPs from being transferred to the addressed SMA if one or more SMPs do not contain the correct management key.
In general, the present invention relates to a system for providing firewall restrictions on subnet management packets (SMP) in a middleware machine environment that can operate on one or more microprocessors. The HCA is associated with the host and also includes means to provide a secure firmware implementation for the host channel adapter (HCA) that connects to the InfiniBand (IB) fabric. Includes means for receiving at least one SMP through a secure firmware implementation, at least one SMP being received from or addressed to the host, and further Includes measures to prevent the host from sending at least one SMP to the IB fabric or receiving at least one SMP addressed to the host through a secure firmware implementation.
The system also includes means for including SMP firewall components in a secure firmware implementation.
The system further includes means for allowing the firewall component of SMP to prevent one or more SMP-based operations.
The system further includes means for allowing the SMP firewall component to prevent SMP-based communication between the host software and the subnet manager.
The system also includes means for implementing special rules as part of the SMP firewall component.
The system further defines special rules that certain SMP-based request and response types are sent and received at tightly controlled rates, and / or direct route SMPs and local identifiers. Includes means to allow you to define source and destination limits for both with the root SMP.
The system further includes means for allowing a secure firmware implementation to include a proxy function, which can receive communication with the host software through a local out-of-band interface.
The system further includes means for allowing the subnet manager to send SMPs to the host software via a proxy function.
The system further includes means for preventing an unauthenticated search of configuration information from a remote IB node.
The system further includes means for allowing the subnet manager to shut down the HCA port that is causing the subnet administrator (SA) request overload.
In general, the present invention relates to methods for preventing subnet management packet (SMP) based attacks. Including receiving at least one SMP through a secure firmware implementation, at least one SMP is either received from or addressed to the host, and further Includes preventing the host from sending at least one SMP to the IB fabric or receiving at least one SMP addressed to the host through a secure firmware implementation.
The above method further involves including the SMP firewall component in the secure firmware implementation.
The above method further includes allowing the firewall component of SMP to prevent one or more SMP-based operations.
The above method further includes allowing the SMP firewall component to prevent SMP-based communication between the host software and the subnet manager.
The above method further involves implementing special rules as part of the SMP firewall component.
The above method further defines that special rules are sent and received at a tightly controlled rate for certain SMP-based request and response types, and / or directly routed SMP and local. Includes making it possible to define source and destination restrictions for both the identifier route and the SMP.
The method further includes allowing a secure firmware implementation to include proxy functionality, which can receive communications with host software through a local out-of-band interface.
In general, the present invention relates to a system for preventing subnet management packet (SMP) based attacks. It includes means for receiving at least one SMP through a secure firmware implementation, at least one SMP being received from or addressed to the host, and further. Includes means to prevent the host from sending at least one SMP to the IB fabric or receiving at least one SMP addressed to the host through a secure firmware implementation.
The system also includes means for including SMP firewall components in a secure firmware implementation.
The system further includes means for allowing the firewall component of SMP to prevent one or more SMP-based operations.
The system further includes means for allowing the SMP firewall component to prevent SMP-based communication between the host software and the subnet manager.
The system also includes means for implementing special rules as part of the SMP firewall component.
The system further defines special rules that certain SMP-based request and response types are sent and received at tightly controlled rates, and / or direct route SMPs and local identifiers. Includes means to allow you to define source and destination limits for both with the root SMP.
The system further includes means for allowing a secure firmware implementation to include a proxy function, which can receive communication with the host software through a local out-of-band interface.
In general, the invention relates to a method for providing switch-based subnet management packet (SMP) traffic protection in a middleware machine environment capable of operating on one or more microprocessors. A means for receiving one or more SMPs addressed to a Subnet Management Agent (SMA) component through a network switch, and A means to check if one or more SMPs contain the correct management key via a network switch, Includes measures to prevent one or more SMPs from being transferred to the addressed SMA component if one or more SMPs do not contain the exact management key via a network switch.
The system further includes means for removing one or more SMPs according to the fabric policy.
The system further includes means for allowing each of the one or more SMPs to be a direct root SMP.
The system also provides a means for the subnet manager to use one or more SMPs to communicate with the Subnet Management Agent (SMA) components through the network switch's unique switch port. Including.
The system further includes means for defining different management keys for each external port of the network switch.
The system further provides a means for allowing network switches to enforce individual restrictions on SMPs sent from external ports to SMA components, and SMPs received on external ports from SMA components. Including.
The system also sends one or more SMPs through the subnet manager by the unreliable remote host channel adapter (HCA) associated with the SMA component when the correct management key is identified. Includes means to ensure that you only do.
The system further includes means for determining the speed of the SMP, which defines how fast a remote HCA port can generate the SMP.
The system further reveals that one or more switch ports are reliable, and SMP requests are sent from trusted ports Includes means to allow SMP responses to be received on reliable ports.
The system further includes means for allowing a single SMA component request to be sent from a trusted port to an untrusted port.
In general, the present invention relates to a network switch that operates on one or more microprocessors. A means for receiving one or more SMPs addressed to a Subnet Management Agent (SMA) component, and A means to check if one or more SMPs contain the correct management key, Includes means to prevent one or more SMPs from being transferred to the addressed SMA component if at least one SMP does not contain the exact management key.
The present invention includes one or more conventional general purpose or dedicated digital computers, computing devices, machines, or microprocessors, including one or more processors, memory, and / or computer-readable storage media programmed according to the teachings of the present disclosure. By using the above, it can be realized as appropriate. Appropriate software coding can be readily prepared by skilled programmers based on the teachings of the present disclosure, as will be apparent to those skilled in the art of software technology.
In some embodiments, the invention is a storage medium or one or more storage media on which instructions that can be used to program a computer to perform any of the processes of the invention are stored. Includes computer program products that are computer readable media. This storage medium can be any type of disk, ROM, RAM, EPROM, EEPROM, DRAM, VRAM, flash memory, including floppy (registered trademark) disks, optical disks, DVDs, CD-ROMs, microdrives, and magneto-optical disks. It may include, but is not limited to, devices, magnetic or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.
Previous descriptions of the present invention are provided for purposes of illustration and explanation. It is not intended to be exhaustive or to limit the invention to the disclosed form itself. Numerous changes and variations will be apparent to those skilled in the art. Embodiments understand the invention using various embodiments and variations suitable for the particular application intended by those skilled in the art by best explaining the principles of the invention and its practical application. Selected and explained to be able to. The scope of the present invention is intended to be defined by the appended claims and their equivalents.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US07721324B1 | Cites | United States of America |
| US20070294405A1 | Cites | United States of America |
| US20050108434A1 | Cites | United States of America |
| US06941350B1 | Cites | United States of America |
| US07113995B1 | Cites | United States of America |
| US07398394B1 | Cites | United States of America |
| JP2004537881A | Cites | Japan |
146 members in 6 offices
Priority claims24
| Document | Office | Kind | Date |
|---|---|---|---|
| 201161506557 | United States of America | P | |
| 201161506557 | United States of America | P | |
| 61506557 | United States of America | – | |
| 201261645517 | United States of America | P | |
| 201261645517 | United States of America | P | |
| 61645517 | United States of America | – | |
| 13545796 | United States of America | – | |
| 13545803 | United States of America | – | |
| 201213545796 | United States of America | A | |
| 201213545796 | United States of America | A | |
| 201213545803 | United States of America | A | |
| 201213545803 | United States of America | A | |
| 2012046219 | United States of America | W | |
| 2012046219 | United States of America | W | |
| 13545796 | – | – | – |
| 13545803 | – | – | – |
| 61506557 | – | – | – |
| 61645517 | – | – | – |
| US201161506557P | – | – | – |
| US2012046219 | – | – | – |
| US201213545796 | – | – | – |
| US201213545803 | – | – | – |
| US201261645517P | – | – | – |
| WO2012US46219 | – | – | – |
Members146
| Document | Office | Kind | |
|---|---|---|---|
| US2012069730A1 | United States of America | A1 | |
| US2012072562A1 | United States of America | A1 | |
| US2012072563A1 | United States of America | A1 | |
| US2012072564A1 | United States of America | A1 | |
| WO2012037512A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012037518A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012037520A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2012079090A1 | United States of America | A1 | |
| US2012079580A1 | United States of America | A1 | |
| US2012307682A1 | United States of America | A1 | |
| US2012311122A1 | United States of America | A1 | |
| US2012311123A1 | United States of America | A1 | |
| US2012311124A1 | United States of America | A1 | |
| US2012311143A1 | United States of America | A1 | |
| US2012311182A1 | United States of America | A1 | |
| US2012311332A1 | United States of America | A1 | |
| US2012311333A1 | United States of America | A1 | |
| US2012311670A1 | United States of America | A1 | |
| US2012311682A1 | United States of America | A1 | |
| WO2012167268A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2013016718A1 | United States of America | A1 | |
| US2013016719A1 | United States of America | A1 | |
| US2013016730A1 | United States of America | A1 | |
| US2013016731A1 | United States of America | A1 | |
| US2013019014A1 | United States of America | A1 | |
| US2013019302A1 | United States of America | A1 | |
| US2013019303A1 | United States of America | A1 | |
| WO2013009846A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013009850A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013009846A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN103125097A | China | A | |
| CN103125098A | China | A | |
| CN103125102A | China | A | |
| EP2617157A1 | European Patent Office (EPO) | A1 | |
| EP2617159A1 | European Patent Office (EPO) | A1 | |
| EP2617165A1 | European Patent Office (EPO) | A1 | |
| JP2013539877A | Japan | A | |
| JP2013541905A | Japan | A | |
| US2013304699A1 | United States of America | A1 | |
| US2013304883A1 | United States of America | A1 | |
| US2013304889A1 | United States of America | A1 | |
| US2013304890A1 | United States of America | A1 | |
| US2013304891A1 | United States of America | A1 | |
| US2013304908A1 | United States of America | A1 | |
| WO2013170205A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013170218A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2013543304A | Japan | A | |
| CN103597795A | China | A | |
| CN103621038A | China | A | |
| CN103621048A | China | A | |
| EP2716003A1 | European Patent Office (EPO) | A1 | |
| US8713649B2 | United States of America | B2 | |
| EP2732604A1 | European Patent Office (EPO) | A1 | |
| US8739273B2 | United States of America | B2 | |
| US8743890B2 | United States of America | B2 | |
| EP2754278A2 | European Patent Office (EPO) | A2 | |
| JP2014517406A | Japan | A | |
| HK1191464A1 | Hong Kong, China | A1 | |
| US2014241208A1 | United States of America | A1 | |
| US8842518B2 | United States of America | B2 | |
| JP2014527330A | Japan | A | |
| US8874742B2 | United States of America | B2 | |
| JP2014529370A | Japan | A | |
| US8886783B2 | United States of America | B2 | |
| CN104170348A | China | A | |
| CN104205778A | China | A | |
| EP2850804A1 | European Patent Office (EPO) | A1 | |
| EP2850811A1 | European Patent Office (EPO) | A1 | |
| US9054886B2 | United States of America | B2 | |
| US2015160937A1 | United States of America | A1 | |
| US2015161391A1 | United States of America | A1 | |
| WO2015084489A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2015517765A | Japan | A | |
| JP2015523768A | Japan | A | |
| US2015244572A1 | United States of America | A1 | |
| US2015244817A1 | United States of America | A1 | |
| WO2015130372A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9215083B2 | United States of America | B2 | |
| US9219718B2 | United States of America | B2 | |
| EP2732604B1 | European Patent Office (EPO) | B1 | |
| JP5844373B2 | Japan | B2 | |
| US9240981B2 | United States of America | B2 | |
| US9262155B2 | United States of America | B2 | |
| US9270650B2 | United States of America | B2 | |
| CN103125102B | China | B | |
| JP5885747B2 | Japan | B2 | |
| JP5893628B2 | Japan | B2 | |
| US9332005B2 | United States of America | B2 | |
| CN105793865A | China | A | |
| US9401963B2 | United States of America | B2 | |
| JP5965478B2 | Japan | B2 | |
| CN103125098B | China | B | |
| CN103621038B | China | B | |
| CN103621048B | China | B | |
| US9455898B2 | United States of America | B2 | |
| CN105981347A | China | A | |
| EP2716003B1 | European Patent Office (EPO) | B1 | |
| EP3077951A1 | European Patent Office (EPO) | A1 | |
| CN103125097B | China | B | |
| JP6043349B2This record | Japan | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 6043349
- Publication, DOCDB
- 6043349
- Publication, EPODOC
- JP6043349B
- Application
- 2014520272
- Application, DOCDB
- 2014520272
- Application, EPODOC
- JP20140520272
Titles2
- Japanese
- ミドルウェアマシン環境においてサブマネジメントパケット(SMP)のファイアウォール制限をサポートするためのシステムおよび方法
- English
- Systems and methods to support sub-management packet (SMP) firewall restrictions in middleware machine environments
Classification
- CPC, 6
- H04L63/083
- H04L41/0803
- H04L63/0227
- G06F2221/2141
- H04L63/0236
- H04L63/162
- IPC, 3
- G06F21 60
- G06F13 00
- H04L12 931
