EDGE-COMPUTE

Securing the Data Center from BMC to Management System

Edge-compute

Securing OpenBMC from Chip to Cloud

As enterprise Information systems and infrastructure expand to hybrid cloud environments shift administration and management from onsite to remote, the risk of cyberattacks for the data center server infrastructure is growing. As new protocols like OpenBMC from Open Computing Platform (OCP) standardize remote management and administration protocols, there is a stronger need to protect systems from the BMC chip all the way to the remote management systems, as we move from legacy IPMI to OpenBMC.

SecEdge’s solution for OpenBMC is designed to protect server infrastructure by:

  • Securing the server device with SecEdge’s SEC-TPM, which is integrated with leading BMC processors like the ASPEED AST2600. This provides a root-of-trust and enables device authentication, secure boot and updates, and encryption key generation and storage. This protects the server from local attacks from the other malicious systems.
  • Enabling secure communication tunnels with SecEdge’s SEC-VPN. This solution enables multiple IPSec tunnels for device administration and management communication.
SEC-VPN Chip to Cloud Secure Connectivity Schematic

EDGE-COMPUTE

Features

  • Hardware Root-of-Trust anchored in BMC Chip
  • Isolation of Access to BMC Chip
  • Secure Provisioning and Change of Ownership
  • Control Plane Isolated from Application Plane with IPSEC VPN
  • Integrated with OpenBMC Management and Redfish Software Update

EDGE-COMPUTE

Benefits

  • Strengthens OpenBMC’s security and integrity
  • Secure Remote Access to the Data Center
  • Secure Lifecycle Management
  • Protection of Software and Firmware Updates
  • Protects Against Attacks from Local Server SW, the Data Center, and Remote Entities

Edge-compute

Partnerships

Interested in deploying a secure OpenBMC solution quickly and easily?