Secure network identity allocation
Abstract
A computer system is connectable to a network. The computer system includes a plurality of processing units, each of the processing units being provided with a respective network identity for communication with the network. At least one service processor is operable to allocate network identities to the processing units. A switch is provided for interconnecting the processing units to the network. The switch is operable to maintain a record of the network identities allocated to the processing units by the service processor and filters network access by each processing unit such that network access is blocked where a processing unit identity does not correspond to that held by the switch. By maintaining a record of the network identities allocated to the processing units by the service processor in the switch and filtering network access, access by a processing unit that has been changed or where its network identity has otherwise changed, can be prevented, maintaining the integrity of the network.
Claims
exact text as granted — not AI-modified1 - 28 . (canceled)
29 . A computer system, comprising:
a chassis, wherein the chassis includes:
a midplane connector configured to receive a plurality of general-purpose processing units, each of said processing units having a respective network identity for communication via a network coupled to said computer system;
at least one service processor configured to allocate network identities to the processing units; and
at least one switch connected to said midplane connector, wherein said at least one switch is configured to maintain a record of network identities allocated to each of the processing units, and wherein said at least one switch is configured to filter network access by each of the processing units such that access to the network is blocked when the network identity of the processing unit does not correspond to the network identity maintained by the at least one switch for that processing unit;
wherein the midplane connector and the at least one switch are configured to connect each of said processing units to the network.
30 . The computer system of claim 29 , wherein the at least one switch includes an array of ports, each port being associated with at least one register for holding a network identity for a processing unit associated with said port.
31 . The computer system of claim 30 , wherein the at least one switch includes a controller operable to receive a network identity for a processing unit from one of the service processors and to store the network identity in the register for the port associated with the processing unit.
32 . The computer system of claim 30 , wherein each port is associated with an array of registers for holding rules for controlling network access.
33 . The computer system of claim 29 , wherein the at least one switch is configured to filter network access, following establishment of the record of network identities in the switch, even if the at least one service processor is not operational.
34 . The computer system of claim 29 , further including non-volatile memory associated with the at least one service processor, wherein the network identities for the processing units are stored in the non-volatile memory.
35 . The computer system of claim 29 , including a reader for a removable storage medium associated with the at least one service processor, wherein the network identities for the processing units are stored in the removable storage medium.
36 . The computer system of claim 29 , wherein said processing units are blade servers.
37 . The computer system of claim 29 , further including a rack mountable shelf in the chassis, wherein the shelf is configured to couple with a plurality of switches and a plurality of corresponding service processors.
38 . The computer system of claim 29 , wherein the network includes a local area network.
39 . The computer system of claim 29 , wherein the network includes a wide area network.
40 . A network identity allocation unit, comprising:
a service processor configured to allocate network identities to a plurality of general-purpose processing units; and a switch configured to interconnect the processing units to a network, wherein the switch is configured to maintain a record of the network identities allocated to the processing units by the service processor, and wherein the switch is configured to filter access to the network by each of the processing units such that access to the network is blocked when the network identity of the processing unit does not correspond to the network identity maintained by the switch for that processing unit; wherein said network identity allocation unit is configured to be hot swappable within a computer system that includes the processing units.
41 . The network identity allocation unit of claim 40 , wherein said network identity allocation unit is configured to connect to the processing units via a midplane connector within said computer system.
42 . The network identity allocation unit of claim 40 , wherein the switch includes an array of ports, each port being associated with at least one register for holding a network identity for a processing unit associated with said port.
43 . The network identity allocation unit of claim 42 , wherein the switch includes a controller configured to receive a first network identity for a first processing unit from the service processor and to store the first network identity in the register for the port associated with the first processing unit.
44 . The network identity allocation unit of claim 40 , wherein the switch is configured to filter network access, following establishment of the record of network identities in the switch, even if the service processor is not operational.
45 . A computer system comprising:
a network identity allocation unit, including:
a service processor configured to allocate network identities to a plurality of general-purpose processing units; and
a switch configured to interconnect the processing units to a network, wherein the switch is configured to maintain a record of the network identities allocated to the processing units by the service processor, and wherein the switch is configured to filter access to the network by each of the processing units such that access to the network is blocked when the network identity of the processing unit does not correspond to the network identity maintained by the switch for that processing unit;
wherein said network identity allocation unit is configured to be hot swappable within a computer system that includes the processing units.
46 . The computer system of claim 45 , wherein the switch is configured to filter network access, following establishment of the record of network identities in the switch, even if the service processor is not operational.
47 . A computer system comprising:
one or more general-purpose processing units, wherein each of said processing units has a respective network identity for communication via a network coupled to said computer system; a midplane connector coupled to the processing units; and one or more network identity allocation units configured to connect to said midplane connector, each of said one or more network identity allocation units including:
a service processor configured to allocate network identities to at least one of the processing units; and
a switch configured to interconnect the processing units to a network, wherein the switch is configured to maintain a record of the network identities allocated to the processing units by the service processor, and wherein the switch is configured to filter access to the network by each of the processing units such that access to the network is blocked when the network identity of the processing unit does not correspond to the network identity maintained by the switch for that processing unit.
48 . The computer system of claim 47 , wherein at least one of said one or more network identity allocation units is configured to be hot swappable within the computer system.
49 . The computer system of claim 47 , wherein each switch includes an array of ports, each port being associated with at least one register for holding a network identity for a processing unit associated with said port.
50 . The computer system of claim 49 , wherein each switch includes a controller operable to receive a first network identity for a first processing unit from the service processor and to store the first network identity in the register for the port associated with the first processing unit.
51 . The computer system of claim 49 , wherein each port is associated with an array of registers for holding rules for controlling network access.
52 . The computer system of claim 47 , wherein each switch is configured to filter network access, following establishment of the record of network identities in the switch, even if the service processor is not operational.Join the waitlist — get patent alerts
Track US2008025292A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.