EDGE-COMPUTE
Securing the Data Center from BMC to Management System
Edge-compute
Securing OpenBMC from Chip to Cloud
As enterprise Information systems and infrastructure expand to hybrid cloud environments shift administration and management from onsite to remote, the risk of cyberattacks for the data center server infrastructure is growing. As new protocols like OpenBMC from Open Computing Platform (OCP) standardize remote management and administration protocols, there is a stronger need to protect systems from the BMC chip all the way to the remote management systems, as we move from legacy IPMI to OpenBMC.
SecEdge’s solution for OpenBMC is designed to protect server infrastructure by:
- Securing the server device with SecEdge’s SEC-TPM, which is integrated with leading BMC processors like the ASPEED AST2600. This provides a root-of-trust and enables device authentication, secure boot and updates, and encryption key generation and storage. This protects the server from local attacks from the other malicious systems.
- Enabling secure communication tunnels with SecEdge’s SEC-VPN. This solution enables multiple IPSec tunnels for device administration and management communication.
EDGE-COMPUTE
Features
- Hardware Root-of-Trust anchored in BMC Chip
- Isolation of Access to BMC Chip
- Secure Provisioning and Change of Ownership
- Control Plane Isolated from Application Plane with IPSEC VPN
- Integrated with OpenBMC Management and Redfish Software Update
EDGE-COMPUTE
Benefits
- Strengthens OpenBMC’s security and integrity
- Secure Remote Access to the Data Center
- Secure Lifecycle Management
- Protection of Software and Firmware Updates
- Protects Against Attacks from Local Server SW, the Data Center, and Remote Entities