End-to-End Server Security with HPE iLO 7
Abstract: From chip to cloud, HPE ProLiant iLO 7 features many security innovations. Presented by Cole Humphreys, Server Security Product Manager, and Luis Luciano, Distinguished Technologist.
During this deep dive session, HPE outlined its comprehensive security approach to server infrastructure, emphasizing that cybersecurity threats are pervasive and increasingly targeting hardware vulnerabilities. HPE identified rising ransomware threats, the growing potential impact of AI in cyberattacks, and the huge financial losses associated with data breaches—especially profound for small and mid-sized businesses. As part of HPE’s Secure by Design strategy, ProLiant servers are architected to provide end-to-end security beginning in the supply chain, through server production, and into operational environments. This includes adherence to a secure development lifecycle, global operational support, and ongoing collaboration with industry standard and compliance frameworks like NIST, FIPS, PCI DSS, and HIPAA.
A central component of this security framework is the iLO 7 management chip, which introduces advanced capabilities such as Silicon Root of Trust (SROT) and a new secure enclave. The iLO 7 chip validates server components before booting, ensuring only authenticated firmware and hardware are allowed to operate. By embedding immutable firmware directly bound to silicon and incorporating new standards like post-quantum cryptography (PQC) compliance, HPE asserts its systems remain secure even against future quantum computing threats. The secure enclave also provides on-chip, level 3 FIPS-compliant key management with support for Safe Erase and backup to external HSMs like those from Talos, allowing customers to store encryption keys in a hardened environment without sacrificing accessibility. Moreover, HPE’s use of SPDM (Security Protocol and Data Model) enables attestation and validation of third-party hardware components such as GPUs, enhancing the zero trust model across external devices and integrations.
HPE also highlighted the centralized security dashboards available through Compute Ops Management (COM), enabling organizations to gain real-time visibility into server health and security posture across large fleets. Moreover, HPE discussed compliance best practices involving log sanitization for regulatory regulations like GDPR and HIPAA, and its approach to TLS certificate management in alignment with modern browser requirements. Beyond firmware and component-level concerns, the conversation expanded to the implications of managing security for peripheral systems like liquid cooling in high-performance environments and how security standards must adapt to interconnected dependencies. The session concluded by emphasizing HPE’s differentiation in the market due to its proprietary silicon, holistic secure development lifecycle, and forward-compatible security features, along with anecdotal examples of how their architecture shielded customers from industry-wide vulnerabilities impacting competitors.
Recorded live at the HPE Customer Innovation Center in Houston, Texas on April 8, 2025. Watch the entire presentation at https://techfieldday.com/event/tfdxhpegen12/ or visit https://TechFieldDay.com or https://hpe.com/proliant for more information.
Transcript
Yeah, we're gonna go through a, a security deep dive here. Some of the questions y'all were bringing up when Darren was talking, I think we'll hopefully be able to get into some of that. And, uh, we're gonna talk about, first the relevancy of the topic and how some of the customer insights we're hearing and some of the regulatory and compliance governance, uh, evolution that's happening, and why that's making some of these changes necessary.
Then we're gonna go into some of the technical, uh, proof points. Uh, we've got Lewis coming in today to go through some of that, um, in detail, and then ultimately kind of have a discussion about what are some of those, uh, customer use cases we see and, and hopefully have a active dialogue at that point. All right.
So, you know, one of the questions I heard y'all ask was, is this something our customers are thinking of? And I would say very much so. And, um, you know, when you look at some of the figures we've been getting through third party research and direct interviews with our customers and partners, right?
We're seeing some pretty disturbing trends, uh, that have happened in, in the past, and they're happening right now, and they're continuing to grow into the, uh, unforeseeable future, right? And so things like, you know, each one of these incidents where their data is compromised, uh, on average it's almost $5 million an incident, right? So for major, uh, companies, that may be something they can absorb.
But for smaller mid-market, uh, you know, this could be, um, it could be the end of, of their existence in some cases. And it is, as it is not a, uh, random act of, of, of security that's going on, breaches continue to rise. And, uh, you know, there were like six, uh, I'm sorry, they average of six security breaches, uh, on average.
And so if you take that and spread that along, you know, $5 million and six breaches, that could be up to $30 million a year being, uh, ex, you know, having business risk and exposure. And, uh, 75% of an enterprise community said that they have experienced some sort of ransomware attack in the last 12 months. And then of all the, uh, it, uh, decision makers we were talking to, 94% think AI is gonna be somehow part of the problem.
While it's unlocking a lot of innovation, it will also become a threat, uh, potential space. So as we look at all this, we're like, well, what do we do? And I, I think this is where HPE really steps up.
'cause well, we'll, we'll get down into the specifics of the compute business unit and where we deliver meaningful security innovations in the server. And ILO specifically, right? HPE has made a pledge that, you know, we are a secure by design company.
And what that means is we actually, uh, are thinking from the very inception of our new products about how to make sure these things are secure through our supply chain and our software ecosystem, ultimately into production, and then out into the, uh, into the wild, right? And when that sounds kind of like secure by design, that's a pretty big topic. So what does compute do when you're talk about, what do you mean you have a secure by design pledge, right?
I think here are the specific things I think that the compute business unit contributes to H HP's overall secure by Design pledge, right? The requirements analysis. We spend a lot of time working with, uh, you know, the DMTF, I heard someone talking about redfish, right?
We lead and, uh, that organization, right? Isn't Jeff the president mm-hmm. Of DMTF right now?
So, I mean, we have leadership seats at DMTF and we're trying to lead the industry, uh, not for selfish gain, but really to try to raise the level of the water and all ships rise you, right? And so we try to lead through there. And then where we get our insights are from a lot of the regulations, you know, nist, FIPs, iso, hipaa, PCI, there's all sorts of new stuff going on that's talking about we gotta keep, uh, protecting our firmware.
We gotta keep protecting our data, you know, a secure development lifecycle. I think one of the areas that it's a, it's a hard part and, and maybe an unsung, unsung hero in many cases, but our su our supply chain, our global operations is pretty awesome, right? So all over the world, we can build these high quality, affordable industry standard servers that can be deployed, um, pretty much anywhere in the world, and then support them and maintain them in a way that is, they're built securely and they run securely, and we can ultimately decommission them and do it all again, right?
So a secure development lifecycle from a secure construct and, and, and architecture all the way through the end of life to do it again. And where we actually make real innovations happen is in the hardware and the firmware security, right? You heard the Silicon Root of trust, big update on that.
Uh, we'll talk about later in, uh, IO seven case, um, software and application security right now that we're getting, uh, you know, an expanded infrastructure management type, uh, portfolio. Our compute software products like OneView and compute ops management have a lot of, uh, responsibility in making sure their software and their user access and the security of the actual code itself is good to go. Access and identity management, working with the GreenLake Cloud platform, working between ILO and compute ops management, all that takes a lot of work to make sure it all happens.
And then inside the server, and even outside the server with HSMs and remote key managers, right? The encryption and data protection requirements where servers, in many cases, while we have our own storage business unit, there are a ton of storage options deployed in our servers. And, uh, you know, protecting that data, encrypting the, the, the keys necessary to, to protect that data remotely or locally.
Um, you know, something we think about and care a lot about monitoring and incident response compliance and certification, supply chain security, and, uh, you know, username, you know, some of these things, you know, we in the compute business unit are one business unit. HPE has a lot of this. Like, there's a global cybersecurity center, just the other across the hall.
I don't know if y'all are gonna get to see that, but that protects all of HPE, uh, and any customer data in our own intellectual property and all that. Uh, we have, you know, professional advisory and professional services that have cyber practices. And in our sister business units in storage and Aruba, we have a lot of, uh, really compelling things that are also unique proof points.
But we're diving in today to talk specifically about the server threat landscape. And yes, I think there was, someone said that even matter. Absolutely.
Um, now is it something you hear in the news all the time about HPE servers being breached in the servers, in, in the customer's environments? No. That, that, that's not a popular news item on purpose because we try to absolutely stay in front of that.
But I promise you this, the digital attacks on the server infrastructure, 100% a real threat, right? Getting a distributed denial of service attack and knocking out the IO ports or somehow getting the brute force password attack on ILO and taking unauthorized privilege over that malware infections and the bio or the firmware of, of the, of ilo social engineering insider attacks. Some of these things, you know, we can't stop a malicious employee from getting ahold of somebody's poorly, uh, managed credentials and logging in and doing bad things.
But these type of attacks, if you can control the infrastructure, you can do a lot of damage. Physical attacks. We just heard the team go through the edge, right?
Imagine you were able to have unauthorized or, you know, un uh, unsupervised access to that device. How much could you do over time? And what you'll hear, you know, us talking about here, even with all that time in the world, you're not gonna be able to hack into like our secure enclave and then the future threats.
You know, we look to, uh, the CNSA timetables and some of these other things post quantum cryptography and the threat it poses to all of our data is real. Now, when is kind of the big question mark, but we are saying sooner than later is the time we want to be ready. Because what is happening is, or in theory is happening.
Everybody's grabbing up all this encrypted data now and sticking it into a vault. And then when the ability to take qubits and, you know, reverse engineer all the RSA, uh, math and everything, they'll already have this. So your social security number, for example, be just as valuable in 10 years as it is today.
So we want to protect our firmware, uh, from, uh, being attacked by a quantum computer technically now. So that in, let's call it 10 years, we'll be, you know, basically future proof from here forward. Are you gonna get more into depth about how you're doing that?
Uh, we will have a section on that post quantum cryptography, uh, support statement that our distinguished technologist Mr. Lewis will cover. If I try to gloss over that, just, just stop me and let's, let's deep dive into it.
Okay? Okay. Um, so one of the things you'll hear from maybe the competition or from our customers are, you know, what is your zero trust approach to securing all of it, right?
I get it. You got a great server, Cole, uh, but how do you approach, let's call it zero trust computing? And I would say, well, let's talk about that.
Because what we can do, uh, as we break that down is from, again, that very beginnings of securely HPE owned, uh, IO asics and our own custom UFI bios, right? And the work we're doing to secure, uh, the, the data, you know, with SCS and the key store and the secure enclave and things, right? We, we have good data protection at the server level.
We're, uh, working with, uh, you know, intel and confidential computing with their SGX, uh, capabilities and things of that nature to build more secure, uh, workloads and solutions to op, you know, optimize that software environment. And then we have secure operations as a service. You heard about the compute ops management and how that delivers that secure firmware, uh, exchange with from a server to a fleet of servers.
And then underneath, right? How we have a, a global operations that securely deploys, uh, you know, from the negotiation and, and management of the individual parts from suppliers into the finished products. And we even have an extra service where you can have that product hardened in our supply chain for that final delivery.
Like, uh, Darren was says, when it leaves the factory and then gets the next touch point, we can turn on a lot of our digital security and even some physical security capabilities. So it arrives in a hardened state. So we have a lot going on under the hood or at the foundation level around our secure operations.
It really builds a zero trust kind of construct from our factories to the cloud. Um, and again, like we had mentioned a little bit earlier, this what we, we enjoy this, we get a passion for security, but a lot of it is the challenges coming out of a lot of new regulations and, and guidelines and compliance that we are part of, and we're being told about from our customers. The bar is getting higher in hospitals to protect the privacy of patient data, right?
In the PCI, uh, world of, of, uh, online financial transactions. And of course, you know, you see the Defense Department of Defense of the US or nist, or the NSA and some of these very opinionated and well documented requirements to really offer high security to protect critical infrastructure. 'cause we, we believe if we can hit that high bar, then we can do just about anything from there.
In many cases, if we can go achieve like a commercial national, uh, uh, security algorithm, is that commercial national security algorithm, right? And so we can achieve those standards and, and deliver against that, that will translate to other country guidelines, other corporate guidelines, because this, to do this will, uh, will be some pretty high secure, uh, high high security, uh, math going on. And so that being kind of, I won't say repackaged, but in a way, we would take that to a hospital group.
We, we'd take that to, you know, maybe the UK government, we could go into the German Go government and things of that nature using the same technologies to satisfy those different, uh, requirements. Oh, if I could, if I could, yes, sir, please out real quick is is that, for example, the efforts that we went through for phis, sorry, um, puts us in a really good position to do things like when we wanna go, go to, you know, sell to a customer. That's, that's, uh, we're P-C-I-D-S-S for instance, you know, we're talking about edge, you know, we have to get it.
PCI certified, P-C-I-D-S-S certified. Well, since we have already gone through the FIPs process, we built the hardware for it, it, it's, it's kind of a no-brainer. It's like when they go through and they, they wanna certify, it's like, okay, the servers are good, we're gonna move off and start checking your point of sales machines and stuff like that.
But it makes it a lot easier to comply with all of this other stuff by complying with the hardest one. So I, I wanted to, I don't want to go too deep into this, but I do want to dig into this a little bit. When you look at particularly the, the, the regs that you, you have listed here, a lot of these are fairly high level data security regs, and we're talking servers here.
So how do you relate from the server all the way up? Like, HIPAA is about the, the exposure of, uh, personal health information, right? GDPR is a data security standard.
It's right, you wouldn't naturally think about GDPR when talking about a, uh, just a bare bone server, right? Yes, yes and no. So Help me understand why it's, what's Going on here.
Uh, take, take, uh, logs, for example, right? It's like they have to be sanitized or, or if it's your own log, you know, that's cool. You're not, but if you're gonna send it to, to HPE or something like that, it has to be sanitized before it leaves the box.
Mm-hmm. So we do things like we sanitize logs, uh, we sanitize, you know, we have this, uh, active health feature, you know, like if the customer's in trouble, here's, here's all the telemetry that came out of the server. Go to HPE and HPE can, can figure out, okay, we think it's a, a dim or something like that.
But those things are sanitized, you know, to be compliant. So you're, but you're specifically talking about, say the server log that the server's keeping in its firmware. Yeah.
In IO in i, so there are multiple logs in ilo. Those get sa, those get sanitized the OS logs, that's sort of outside of our area, Right? That, that's where I was trying to get through is like the, right, so I am, I'm still a little bit, like I said, I don't wanna derail the conversation too much, but it does appear that, um, I'm, I'm having trouble with a server having in an IO log, having access to the type of stuff that would be covered by hipaa, G-D-P-R-P-C-I-D-S-S.
I'm trying to figure out where, where a payment card is gonna show up in a server firmware log. P-C-I-D-S-S. Yeah, That's a Lot of, it has a lot of requirements from a physical perspective, from Physical server, from Physical security, yes.
Things that are kept inside of the ilo. It's not, you know, payment cards and not nothing like that. Yeah.
It's really, it's really, uh, who authenticate, who logged into the IO uh, you know, three tries and, you know, that kind of stuff. Okay, thank you. The, the security people wanna know that, you know?
Mm-hmm. But that's their data. That's not, that never leaves the box unless they send it somewhere.
Gotcha. You know, we don't, we don't, we're not in there. Okay.
So you can ensure that the accessibility, if, for lack of a better phrase, an ACL for pertinent data is maintained by, by right. By segregation or by design. Yes.
You have to export it. It's not gonna do anything on its own. Yep.
Okay. Those kind of things. Good question though.
That's not a derailing. That's good. And, and, you know, sometimes the, uh, command and control of that server, which is hosting all that.
So if you were to get an unauthorized access to IO, you could do some pretty bad things. Or the bios, right? You corrupt the bios, corrupt bi, uh, IO you could disrupt, like basically take offline the server that's got all your encrypted data on it or wipe your keys out and all your encrypted data is now gone.
Mm-hmm. Right? Or lock it up and now it's, right.
So it's about controlling the server itself, which is the storage, like, uh, appliance, if you will. If you've got control over the host of all those drives, you could be disruptive. Not that it's gonna go see all the drives itself, right?
Mm-hmm. I guess the only thing would be storing maybe the SED keys. That would be the direct one-to-one connectedness between data security and Right.
Ilo. Right? And it's a management plan.
If you were to have access, then you have DLP potential, you know, exfiltration, DLP, whatever you want, you know, necessary. Correct. Okay.
Thank you. And yeah, so any questions like that, feel free to stop us. We don't want to just present one way to you.
We wanna make this as, hopefully these are stimulating some thoughts here. Uh, you saw this in Darren's slide. We like this one.
Uh, you know, because it's, each one of these by themselves is kind of interesting, but it's like, you know, it's not going to stop everything. So this is where everything's kind of built for a purpose. You know, really kind of building off the foundation that we like to talk about our global operations, secure supply chain.
And then, uh, you start building on top of that, you get into some of the cool stuff. We're gonna talk about the actual server itself, the security that is baked into that, and it can support. And then it starts getting kind of cool.
And then let's say now you got a thousand of these servers all at the edge or whatever, now you can use our tools to, uh, you know, manage all of these. And, uh, one of the things in compute ops management, that it's got a security dashboard. So just like each ILO has a security dashboard that you could manage and see what's going on one at a time, that kind of construct of all the APIs roll up into comm.
So if you have a thousand servers and number 768 has a state change from, you know, green to yellow or green to red, you're gonna pick that up and be able to seek faster insights about your fleet security and be able to manage that. So that kind of all together is what I think we're most proud of. Because one of the things I heard from our compute ops management, uh, uh, planners, I, I was like, that's kind of cool, is I believe, and we believe that it's almost like a five factor security, you know, offering that we have real command and control over, right?
You know, factor one, uh, is probably, you know, some of the identities that we can put into the, uh, supply chain. You got factor two, uh, gets into the device, um, and then it goes up all the way, you know, then you got GreenLake and then ultimately the compute ops management. So, and so you put kind of the, uh, supply chain, the device, the io, the GreenLake, and then the compute ops management, all in those as five factors of authentication you would have to clear to get true control over your whole solution.
That's pretty powerful. You have a question on the, the, the immutable source in silicon, right? Uh, we found out, you know, uh, there was, uh, some bio UEFI stuff that vulnerability gets found much, much later in code that was implemented and or, or a technique was found to get through something.
Can't that immutable source in silicon become itself a vulnerability? If, you know, something is found later and it's very, very difficult to Change. I think that's the next slide we're gonna get, right?
We're gonna get right into that. Oh, I, why we think that's not the case. You Get a good segue.
Let's shift gears. Alright? How Works?
Okay, let me, uh, before, before we get into the details like that, let me just sort of explain how, what, how we're thinking about these kind of things and how we arrive at, you know, 'cause you're gonna see a lot of features and stuff like that. They're not disconnected features. They, they follow a strategy.
Okay? So we, we believe, uh, the people, the people in this room, we build servers, right? So there are the parts of the company do other stuff.
Um, we believe, uh, that there's a DAA boundary between the data plane and the security plane. In other words, the, and, and people define that boundary differently, but for us, the, the d the, the separation is between the hardware and the software that's running the os, the hypervisor, you know, customer workloads, customer data, all of that's data playing. Okay?
And then underneath is, is the, the management plane, or other people call it the security plane. So that's the hardware. So, so there's, the software has to be able to trust the foundation, the hardware, so that, that's, that's clear.
The, the foundation does not trust, you know, the software that's running up there. It can't, uh, it has to, it has to trust itself. And I'll go one step further.
The hardware can't trust itself even at the beginning because there are supply chain issues and stuff like that. Somebody can swap out something. And so everything gets validated from the very beginning.
So what, how do you, how do you manage that? So we have, you know, we talked about the IO chip. The IO chip is kind of central to all of this.
And then central to the ILO chip is the ilo. Not only the firmware, but the silicon. And then that is what we call silicon Rooter trust.
And that's, that's, uh, that's what I'm gonna show right here. So Silicon Rooter trust, why is it, it's a, to answer your question, it's why is it, uh, that we consider UFI to be immutable? You know, that's not immutable, but it's, it's, it's, uh, immutable in the sense that, uh, only validated firmware can run.
Okay? So, so, but it starts with some immutable firmware. So for us, we make our own silicon.
So that gives us the advantage that we can, we could hard bind the immutable firmware to the silicon. So what that really is is it's, it's very simple. It it, you know, as Darren was saying this, this was, this was in 2017, I think is when we came up with this.
But what it really is, is that, is that, uh, the silicon itself goes off and takes a measurement of that immutable firmware. And then if it's good, it, it, uh, I'm simplifying it a little bit. It copies it in a, in an internal memory.
And there are other things like to prevent certain types of attack that we, we do it this way. Um, it, it's, it's an internal memory. We validate it, it's good, and then it kicks off this chain that we're talking about.
That's, that's right here. So that firmware's good, ILOs good, you know, then ILOs up and running. Then ILO starts checking other things that are within the chassis, including UFI firmware.
So all of this before this server even powers up, so this is when you plug it into the back, uh, something called auxiliary power. So we have ox power that's powering something's in the box, including ilo. So ILO goes and checks all this stuff.
If it's good, then the power switch is enabled. You can power on the server or it auto powers on, or however you wanna set that up. So that's, that's how that works.
Uh, so that's what this is showing. So gen 11 and then, and before you'll see it starts off with the ILO starts off with the silicon. The ILO six hardware in this case, uh, jumps off.
It validates the firmware. And then while it's doing that, it's spreading itself out. So it's, it's a root of trust.
It's truly, you know, working its way out, checking all these devices that are out here, including the UFI bios. So the BIOS is attached to the ilo so it can go off and do this stuff before, it doesn't need any CPUs or anything like that to do it. So it's good.
Uh, um, and then it's allowed to boot. And you'll see the, the UFI BIOS goes off and you can tie it all the way through other mechanisms to, to the actual OS boot loader. And then from there, so the trust, the everything is checked, you know, all the way up to the os.
And then it's up to the OS to do what, what's later, uh, what we did in gen 12. Excuse me. So, so this is pretty, uh, I'd say pretty bulletproof.
But the, the, there's always a thinking about, um, you know, what keeps you up at night? What are the kind of things, how can we raise the bar? 'cause, 'cause the threats are getting worse and worse and worse as you know, and it's, it's not just, uh, you know, hackers and stuff like that, but nation states and things like that are really the, the attacks are becoming more sophisticated.
Uh, you know, our nightmare scenarios are some kind of zero day or something like that in, in, in our product that we gotta, we have to make sure that that can't, you know, ever happen, it can't be exploited and so on. So we raised the bar Gen 12. So what we did is, within Gen 12 is one of the things we did is we added this, this, this auxiliary processor within the ASIC called a secure enclave.
We, it's, it's a secure enclave. It doesn't have a name. Um, so it's, what it does is it's isolated from everything else.
So it not, it's isolated except for two input output. Oh, I mean, an input and an output buffer. In other words, it was designed to, to be resistant against things like buffer overflows, I mean, uh, uh, buffer overflows and, you know, the, uh, things like that.
So, so you, you could only, anyway, we can go into details there if you wanna talk about that. But it's, it, it's, it, its own little container there. Its job is to do what this guy used to do.
So it goes off and validates itself, validates the firmware, uh, before it allows even ILO to run. Not container. Huh?
Not container, not what do you mean? You said it's in its own container. It's No, no, not, not literally container, sorry.
It's own box or something. Like whatever you wanna call it. Yeah.
Memory is own the story. Yeah. Hold on.
No. Okay. Um, Um, effecting on all this, um, one of the concerns that some, uh, ProLiant users have Faced with is, what about third party hardware?
If I'm gonna need to install a third party card, or let's say third party memory or something like that, um, how can you, is that outside? Is that exempted? Oh, no.
Secure Requirements. Thank you. That's a great question by this.
Yeah, that's a great question. So, so you'll notice it, uh, is it on here somewhere? Started here in Gen 11?
Yeah. SPDM. So, so there's an industry standard from the, uh, DMTF, you know, the same folks that brought redfish called SPDM.
And these, a lot of these devices, it's, it's kind of a hodgepodge right now, but a lot of 'em are, are, um, new devices are showing up that are SPDM capable. So what, what that means is that IO can use an industry standard me mechanism to go authenticate and attest those two things. So what does that mean?
Authenticate means, I, I, uh, they have a certificate. We go, do, we go, you know, we know that this is a valid, you know, whatever you wanna call it, ACME Corporation, uh, PCI card. It's like, cool, that's great, but we wanna know what firmware's on there too.
So we, that's the attestation phase. So it sends the same kind of measurement like we, we had for silicon root of trust, it goes into the IO and then ilo, uh, here's a whole bunch of stuff. It's like, I ilo doesn't know anything about third party firmware or whatever, but we bundle it together in a redfish interface that something like Calm, or, or anybody that wants to use the redfish interface can go get all of the measurements for all of this stuff, right?
And, uh, what you can do is, if you wanna do this at scale, is you can keep track of all those measurements, and you can point out, it's like server number 75 has old firmware and it's power supply that has this vulnerability. You know, it's, it's legit firmware, but it's, it hasn't been patched. So that's the, that's the reason why the attestation.
But anyway, so, so the, the goal here is to cover, you know, inside of the box all of the, so we, we go and rank things like by threat, you know, by threat, by, by how exposed it is and stuff like that. And to get the really, the bad ones, you know, the bad ones in a sense that, that this, these are targets, right? So the get those covered by this kind of stuff is, is, you'll see, that's the thinking behind gen 12.
That's the thinking behind, behind our next generations with stuff we're working on now is, is how do we make sure that this box is secure. Um, anyway, so any questions on any of this? I, I, I have actually have a question, which is the secure enclave, is that just acting as a walled guard, walled off processor for ilo?
Or is it actually also doing like a TPM with encryption and one way certificates? No, it, it, it is, it is, it is two things. It's what I just talked about.
Well, it's many things, but the two big things is what I just talked about. The other thing is it has secure storage, a lot of secure storage. Okay?
So the idea is that it, it's not a customer. It's not like I wanna keep my keys in there. Like, it's Not like a traditional TPM that No, but it's just for ilo.
But think of it as a, I have an SED, where do I keep those keys, right? So the idea is that I need a, I need a safe, we will talk about that, but it's, it's a, I want a safe place locally to keep my keys. And then we have a feature where you can back up those keys just in case, but okay.
The idea is that we wanna, it's in a FIPs. We're, we're seeking FIPs one 40 dash three level three. Okay.
So, we'll, we'll go into why that. But, but, uh, your, your keys at rest are always within a one 40 dash three level three container. In other words, they're protected against physical attacks.
And what's really important is, you know, they're your keys. It's like, if you delete the keys, you've lost all your data. Yeah.
So, so we, we wanna protect against deletion, you know, all that kind of stuff, you know, physical stuff. And we will go through that in a, in a second, why. But, um, So this is the, in it to one of my questions in the earlier session, this is a delineation between groups from a practical perspective, the, um, infrastructure team is responsible for implementing this, uh, making sure standards, so you know, the redfish level and making sure I can deploy it, et cetera.
The ops, the network ops team is responsible for identifying incidents and making sure mm-hmm. That the infrastructure is compliant, that incidents are being responded to, et cetera. So from a tooling perspective, those are not necessarily, even if they're the same tools, they're not the same groups functionally in the enterprise.
Mm-hmm. Mm-hmm. How should you know, CTOs and CISOs be working together to think through this layer?
Because once we leave this layer and go up to the OS app layer, et cetera, you guys are kind of out of the, that's right. The picture a little bit, But where you talked about what's a CISO gonna hear versus the infrastructure decision maker, right? Right.
I think you would probably talk more at that. Uh, we have this zero trust computing implementation from our secure by design from our global operations, and then Proofpoint proof points, right? We have a product, uh, security response team that Scott manages that keeps up with all the vulnerabilities, and if we need to patch 'em and do a support bulletin and all that, uh, we have, uh, other activities other than just the infrastructure that a CISO's gonna care about, right?
How are you delivering a secure solution HPE, whereas the infrastructure decision maker's gonna geek out on what's different gen over gen. Mm-hmm. And they're gonna want to know, like, prove it.
So it's a kind of, they're complimentary, but at which altitude you would drop, uh, drop into. But what's important I think, is that we're working very closely with like the HPE product security teams. So this is just a representation of what HPE can deliver.
So they kind of can go wherever you need it to go. You could go up the stack to a CIO or a CISO and talk about how our whole security philosophy is HPE can be down to the actual servers we manufacture and sell. Uh, or if you're just the infrastructure person, we'll talk about what's new in gen 12.
So it's kind of a threaded story, but it's kind of, uh, choose your own adventure, right? So if we're talking to a ciso, we'd probably go further up in that deck and talk about our secure by design and zero trust computing proof points. Whereas today, we want to kind of love on our server Correction.
So the conversation would be, you know, the title is the Sessions cloud, so I'm not venting something here, but from GreenLake down Yes, sir. Talking about how the overall approach is integrated from all the way from the highest level of extraction all the way down to the Hardware. Yeah.
Yeah, 100%. All the way down to our global operations, like factories of combining things to deliver the server into the indu, into our partner or to our customers data centers, whatever. But it's up and down or down or up.
However you kind of do it, it's that those five areas that we believe, uh, have some significant security benefits to that overall solution that would manifest itself in that GreenLake, uh, really the compute ops management is a great use case of all of it together. And most, most of these things you do, you don't really have to worry about that because this happens automatically. I don't have to do, do I have to make some kind of decision when I buy the server or anything like that?
It's like, it's, it's there, you know? That's how it works. The only, the only time it comes into play is like, oh my gosh, it didn't boot because this power supply is not legit.
So how, okay, now what do I do about that? But, you know, we're not, you know, So h HP is really leveraging their r and d and they're flexing their DNA about that. I mean, it, it, it's obvious, you can see the evolution from SROT, this generation, the additional features.
How are you seeing market competitiveness that they're failing to, to meet the standard? I mean, uh, I mean, here focusing on your features, but what features do you think are unique to your market space that peoples can't even touch? You know, Sorry, that's if, uh, we did Silicon Root Trust and we were the first, and we saw the market com, uh, try to copy it, but they can't copy it all the way because, for instance, they, they buy off the shelf, you know, b uh, BMCs if you will, right?
So, so you can't, you can't really tie it to the silicon all the way to the fab. You have to trust, for instance, the factory that builds it. For instance, the factories, the thing that inserts the keys and things like that.
We think the factory isn't, shouldn't be trusted. We don't, when we build our servers, we don't trust the factory. So things like, uh, generating secrets happen within the IO not, not they get pulled in and inserted into the ILO or side, you know, through, uh, side loading or whatever.
So it's just stuff like that, you know, so we go to extra efforts when we build it. So we think, uh, that's, that's how we differentiate on these things. Uh, the, the secure enclave takes it to a new level, and, and nobody's doing that right now.
I'm sure the people will and all that, but not nothing that we know of right now. So that, that isolates this process. It's really hard to get into that, to, to disrupt it.
Then The final follow up question was, what is the, what is the proof of proof of value that you've seen in the field deliver this to the, from, from the customer? How have they validated your thinking as an organization? How are they validating it?
How are they validating this? Are there use cases that are like shining, say, look, this saved our butt, you know? Well, I have a couple you can share.
Lemme start. Yeah, yeah. I was gonna say, I can't share all of them, but, um, there's, there's one that I think internally is a kind of a unspoken hero in, I think we were doing the math on it, and there were say, general, uh, UEFI bios, um, compromises that impacted others, but because we had our own designed code and our own silicon root of trust, right?
The customers just don't have to experience that disruption, right? So while the industry may have to go worry about how am I going to patch my firmware and recover from this, it's just basically a non-event for HPE customers. So that's probably one, the, the, the absence of disruption when an industry event happens like that.
'cause like take an a MI bios, I, I think if you read like the Google, uh, black hat presentation from last year, they talked about these vulnerabilities that impacted a lot of industry standard servers. We were not included in that. So not being disrupted because of something I think is a hidden benefit, not quite as exciting and as proactive.
But if a non-event happens, uh, for security, that is a win for us. Kinda like a must be how, like the CIA and stuff feels, what, like, you never hear about it, but yet you don't have to. And that's kind of the, the hidden benefit.
The other one would be a little more proactive. Like, uh, Lewis was talking, um, we had some of these capabilities that are pretty powerful. Um, what, and, uh, I'm trying to soften this one up.
There was an event for one of our partners, and it was very disruptive to a lot of their enterprise customers. Um, and so there trying to figure out how to recover from that. And one of the areas they found that IO could help them with is they were struggling in some of the, the booting of an operating environment.
Well, because ILO has the ability to be able to get into the system, they were able to figure out how to actually boot a golden image off using the power of the BMC and then recover those operating environments. So the, uh, application of some of this is designed to be a security powerhouse, but it also gives some pretty significant capabilities to the operators who are using this infrastructure and it could actually help 'em recover, uh, above the stack. Do you have other examples?
Okay. Oh, uh, That Work? Thank you.
Yeah, just proof positive, basically, we don't, we don't need a, a, a, you know, a backpack with a range cover making, you know, a solution for a problem that doesn't exist. Right. Okay.
That's fair. I guess when we talk to customers, ears perk up when we start talking about these things so that, that, you know, it's anecdotal, but, uh, I don't have any numbers or anything like that. Oh, thank you.
I I actually have a big, uh, bigger kind of big bigger picture question. Uh, many companies are so scared of firmware updates and the, the challenge is just the, the, the, the challenge of updating it. And also what could go wrong if you update it, that they recommend that their customers don't update firmware?
Does HPE recommend that their customers do keep their servers on the latest? Well, I think, yeah, I, I understand the mindset of like, what can go wrong when I, you know, all the things that can go wrong when I update the firmware, but from a security guy, you want the latest patches, you know, because, 'cause they're, they're, you have millions of lines of code and stuff like that. There's, they're bound to be things that are wrong with it.
And we'll discover 'em as soon as we discover 'em, we hop right on it and, and we fix it immediately. So you, you, you, from a security perspective update whenever we do it. And I think what we've done to compliment this is the product that you, uh, hopefully have been able to experience was the compute ops management, right?
That does a couple things. One, it's gonna show you this is a critical firmware, right? Or a secure, like, so it give you color coded dashboard of like, maybe you shouldn't.
Yeah. So we're just saying, Hey, you know, I understand your policy is to just skip until some maintenance window in a, you know, monthly or quarterly or something. But this one is maybe higher risk.
So one is information, the other one is a better user experience because the way you patch the firmware with comm isn't quite as laborious. You can just patch the bits that are impacted, right? So it's a little lighter, a little, uh, less intrusive and in some cases may not force a reboot where some of the problems are.
I can't experience the downtime. So we've tried to lessen that ex uh, uh, the pain by making comms firmware update experience better. So you've got information to know, kind of red, yellow, green, maybe you should or, uh, pay more attention to this one.
And then also an, uh, ease of use implementation in our products, like compute ops management. But other than that, you know, that's about all we can do. 'cause sometimes, like you said, they just can't be down, but we'll give 'em the information and, and the tools to do it better.
0 and pq PQC. 0 is from the NSA. And they've sort of, they've, they've not sort of, they've, they've put out a timeline.
0 by these certain dates. You know, they did that before you, I dunno if you saw the old one that showed, it showed a timeline. Like for instance, firmware signing is one of the first ones.
In other words, they're, they're, they've, uh, what is the threat of p qc post quantum computing of these post quantum computers? And they assessed, uh, you know, like it was discussed earlier that, that a post quantum computer that comes into being like 10 years from now after several miracles happen. But if it happens 10 years from now, what can I do to the data that are really the things that exist today?
So one of the things they're worried about NSA and, and I guess others is, is that firmware that was signed today, you know, our, you know, servers that we're shipping today, uh, can be cracked 10 years from now. In other words, uh, what they do is they can extract the private key out of the RSA, you know, signature block that's on there, create their own private key, and sign some malware and get it back into this server that's still in production 10 years from now. So that's why, you know, that's why the timeline originally, that's why in gen 12, our focus was on firmware signing.
So there are two things we do in Gen 12 that's, that are, that are post quantum, uh, resistant is the root of trust that we're talking about. So that's what changed. Another change in gen 12 is that that chain is now using a, an algorithm called LMS that is PQ resistant.
0 compliant. com or whatever it is signed with LMS as well. So in transit, it's also protected and in accordance with that.
But that's more than so that, that, that gets us our gen twelves in a good state, you know, as far as compliance is concerned. Uh, but they get the timeline starts tightening up, you know, the, the restrictions get worse and worse and worse. Uh, if, uh, NSA published a, an FAQ, um, I think it was in November, I can't remember.
It was, it wasn't that long ago where they pulled in, they had timelines extending all the way out to 2033, you know, when they have to be compliant. But now it's a lot tighter. So it's to where, uh, NSS type type systems have to be p qc compliant entirely in 2027.
And then there's an executive order that, uh, the Biden administration put out in, in in January. This says it's not only, uh, NSS systems, but they also mentioned in the, and if you look, if you look at the details that I think it was the Department of Commerce, but, uh, they're in charge of the non NSS systems. So that implies that, well, everything we sell to them is gonna have to be PQC starting in gen.
In other words, they're gonna stock, they're gonna, they're gonna buy only PQC things starting in 2027. Mm-hmm. And their entire fleets have to be p qc compliant.
I think it was in 2030. That's right. So that the timelines are upon us.
So what does that, um, you had Asked for some deep dive on this topic. Is that getting you there or Yeah. Where do you want to, where are you feeling?
Well, So it's some of it. So what, what do the, because I haven't looked at these at all, but what type of things besides the, uh, what did you talk about Besides far more signing and root of trust? Yeah, so, so there's also, for instance, TLS Yeah.
You know, so how the TLS connections, all that after, so it's really anywhere that you use what they call an asymmetric algorithm. So, uh, R-S-A-E-C-D-S-A are the two, you gotta get rid of those. And then the other ones, the other ones are like, you have to have a high strength, uh, as for symmetric, and that that's, you know, most people already have that.
And then, and then hash algorithms and, and things like that. So those, but the big ones are the two, the, the, the asymmetric ones. So think, think of a, so, so when you're connecting to the IO or whatever this device is, TLS, uh, the certificates you use, you're using certificate based authentication.
All of the authentication we do within the chassis, like SPDM we were talking about, you know, it's, it's really, it's like, uh, is it everything in there that has to be it? I mean, it has to be p qc, or, or is there some kind of like a, a, you know, a gray area? It's like anything below that.
Like, I don't really care about fans, you know, stuff like that. Um, that, that's the, that's the challenge for us in, in the industry right now is where, but we we're taking it very seriously. We're assuming the worst.
We're driving it down as far as we can. So 27 is only two years away, right? Mm-hmm.
Yeah. And So you must have been working on this for a really long time because like server production about Two years ago, points Are so long. Okay.
Yeah. The fort more signing. And, and it is more complicated than that.
It's like LMS is the, it was the leader at the time, and now the industry seems to be preferring another algorithm called M-M-L-D-S-A. And so, so we're gonna have to switch and you know, there's, there's that kind of stuff. But we, we'll, we have that.
We can do that, but it's also, who does the signing? Is the signing a legitimate, you know, is, is it certified? You know, all that kind of stuff.
Or is it just somebody you know, you know, somebody on a laptop sign, sign the firmware? Of course not. It has to, you know, we have to be able to, you know, there has to be an audit trail and it has to be all, you know, due diligence all the way down to, to, to the signing.
So it's, it's, it's hard. So can we, can we dig in a little bit on, on the TLS connection? So, and, and I'm not an ILO user when we connect to ILO or we connecting just using a web client.
Is that what we normally do? Yeah, Just a plain old, A plain old web plan. All right.
Yep. So one of the things that's happening in the web world is we're moving towards shorter lived certificates, right? Mm-hmm.
One of the risks is you have a long life certificate, the certificate gets cracked, then you mm-hmm. Right? So you wanna refresh certificates.
So the web clients, the browsers are moving from two year accepting certificates that are, that have a life of two years to a life of one year and will eventually go down to a certificate life of 90 days. How is ILO going to sort of handle that? So we, we have the ability to handle that.
It's up to the customer. I think what we're talking about here is the certificate that's in IO. So, so when I'm in a browser and I want to talk to, talk to I the ilo, right?
I, you know, do I trust that certificate? Do you trust that? Exactly.
And I have a policy that says, uh, I'm not gonna trust anything that's more than six months old. Yeah, exactly. So, so the way you can mitigate that is you, you just install a certificate every six months Okay.
Into the IO. So, so you're right, you're good there. Okay.
I mean, uh, there's nothing else. Uh, this, there's, when you buy the server, it has, it's not a selfs that, that's self issued certificate that comes in there. Mm-hmm.
Right? And that, that's good. You know, common sense security practice, don't trust that you need to put your own in there.
Okay. But a lot of people don't. They just use that.
And then if they use that, of course, that that isn't, you know, it's gonna last as long as you let, let it stay there. Mm-hmm. Um, but it's the same thing.
So that's web, uh, through redfish, you know, all these interfaces use this, you know, it's the same mechanism. Okay. Okay.
Alright. So, so that's, that's, thanks for bearing with me through this. So we we're good on PQC and CNSA, I guess.
Okay. And then, uh, oops, there's more on that. So this, this is the timeline.
This is the timeline that they announced. It was good up to, if you go on the, you, you can't even find it on the web anymore. This was out on the web there before.
Um, this is a timeline they had as of November, and then they changed it with that FAQ. So everybody's like 2023. Ah, I don't care.
It's like, whoop, they brought it to the left. Um, but that gives you an idea of all of the, the kind of things they used to break it up. This isn't that old.
That's the thing is that that's how fast these things are changing. But this niche equipment category is the one that we've, you know, we're worried about inside the hardware. So what is, what is niche equipment?
That's, I mean, it's obviously anything that's not the other things, but that's, uh, fans and, and things like that. So how, how do we secure all of that stuff? And then who would ever want to crack into a fan?
You know? So you're sort of thinking about that. Well, Somebody might want down or speed it Up.
I think that, Yeah, I could great. I commanded Look up fu look at What you, I was gonna say, there's real world, a bunch of H two hundreds. Right.
Very quickly, very quickly by Messing with the fans of pumps. Absolutely. Well, It's the, the same questions Us, right?
Yeah, Absolutely. So, so that's, that's, that's like at the bottom. So power supplies, you know, voltage regulators, you know, CPDs, you know, all that kind of stuff is, is you can do a lot more damage than just the fan.
Yeah. You know, the fan, maybe it'll thermal trip and all that kind of stuff if you, if you, but still it's, it's, it's a hard problem. But most of the stuff within my server is pretty static during the life of the server, with the exception of maybe drives and memory that those things get changed out pretty quickly.
And while memory is a big component of my security, uh, thing, I think we've, we've gotten how to replace Dems without much of a security incident. What is changing is the pace of which we change the, what's becoming more and more of the core compute, which is the GPU, and how are we thinking about securing that GPU thing that is now more important than my CPU and running the vast majority of my compute, I might change that out two or three times in the lifecycle of the chassis. So how should I be thinking about IO securities related to the, from Us?
So, so, so you'd be using SPDM to go to the GPU to to, to authenticate the GPU and get its firmware measurements from that. And that's how, that's, that's so GPUs, dpu, you know, would follow that path. So I dunno if that, but, but that lets you, you know, so that goes out to your management tools.
You could see the firmware's obsolete or up to date or whatever. Yeah. I think one of the things that we've started to trust with Intel, a MD, their secure enclave, their ability to, uh, secure compute, we, we trust it.
I don't know if GPU manufacturers have gotten to that level of security yet in the, at least communicated. So NVIDIA is, is A-S-P-D-M enabled device, right? And we have that SPDM kind of check in from ilo.
So you, once you get, there's a section called global component Integrity, where you would go in and say that. So let's take your scenario and say, look, I'm swapping my GPUs out and I know I'm getting SPDM enabled GPUs. And so when you drop that in and you have your global integrity checks on, they're gonna do that attestation that Lewis was talking about and make sure, hey, this is a known good device with a known good firmware.
So you can't drop in an infected GPU and kind of compromise that system. So kind of ILOs check in that device, uh, out to make sure it's good before it drops into that host server. You guys bring up a very good point.
So we're talking about the cooling in the fans and, and all of a sudden I'm starting to think, 'cause I work for Equinix, right? Big data center company mm-hmm. Lot of liquid cooling.
You guys are all over us, right? Um, so we've got all this great stuff for attestation and authentication, other stuff in your box, right? And, and we wanna also secure all this liquid cooling.
Especially when you get to the NVIDIA stuff. It's like on the what? 2 seconds without liquid cooling and you fry a chip for good.
Right? And I think the GB 300 is gonna get worse, right? It's gonna get probably less than that.
So, um, are you guys looking at extending the, the perimeter of where your management goes to include the liquid cooling plant or the, or the surrounding foundation? Outside of the box? You mean?
Outside of the box? Because it's, because the box now is dependent upon these other things around it. I mean, we already have some stuff for network, right?
We've got GreenLake can do, right. But the surrounding infrastructure, 'cause like you're gonna be using someone else's stuff, but they're gonna be able to feed you event feeds. It would be feeds of, of, of li liquid, of, of the, uh, the environmentals for Instance.
The, the thinking there is that some external tool like calm or something like that would Be some stuff, right? It make Sure that, that the server's okay, it makes sure that, it makes sure that the co liquid cooling and all that's okay. I don't know if we've done that yet, but that's the, that's the framework of, of i i, that that's the way of thinking how to manage these kind of things.
Yeah. Right. And then the area that we may not be able to like do it directly, the support for like redfish APIs will take these and they'll be able to aggregate into like Splunk or if you got some sort of d uh, whatever the doing the cooling and all that sometimes are, are like facilities, programs, what I'm talking about.
Right. And so infrastructure and facilities don't naturally have those conversations. So that's where there would be probably a partner in between there with some sort of SEIM or some sort of the API would be pulled in and then mitigated with that third party software.
We don't, that I'm aware of, have any specific outside the box management that would work with other software except for our own HPE uh, portfolio. I understanding that you do need that information to properly manage these systems and, and to mitigate, you also need to secure that information and make sure the information is correct. It's authenticated using some of these same techniques.
You don't, don't wanna be getting some rogue operator sending you data saying shut down your system. It's gonna get hot. You know, a pump's going bad when it, you know, when that's been maybe some rogue operator is coming in here and, and, and, and.
Right. That's a good thing for us to think about. I honestly, like I said, the strategies that is some management software's gonna handle that.
Um, I mean look, if you're gonna make it, they're always gonna go for the easiest way to disrupt you. Yeah. If you're making it really hard here correctly, Go somewhere else, they're gonna, It's gonna go for an easier way to do it.
Right. And if they can now have a dependency, they can shut you down. Easy target.
Right? Well, so whoever's, someone's gonna have to have the credentials to come in and tell nylo to shut down. You're gonna have to have what?
Username and password at 'em. Yeah. But if the data you're getting from the, from the facilities data comes in and you've triggered stuff that would shut it down based on that information coming in.
Mm-hmm. I'm just saying that this is not necessarily within your chain of trust, but I think you maybe have to work like, But it's like a, you're gonna have 360, you're over here cutting this and then they Able trust that, that information coming in. So how do you do that?
Maybe extending some of these techniques that you have to create a trusted partner of data coming in. Right? Yeah.
That's, this is gonna be very key in, in these as we build these big things. 'cause I mean, if I can't, if I can't take you down from an, you know, inside your box, I'll find another way to do it. Right.
If I'm a rogue operator, not me. So if we had a partner or something or a, a defense on that particular front that would help close that concern you just brought up. Yeah.
They'll always go Roger that. Well thank you for that feedback. That's good though.
I like that. 'cause that, uh, we hadn't thought about that directly, but we can take that Feedback. So I always think about it later.
Alright, Whoever's watching, don't do that. Don't do That. On, on this next one.
We already talked about it, but, uh, uh, I'm trying let, if, if we have any discussion or any questions anymore on, on the secure enclave, this is a good, good place to, to talk about it. Um, this is just to illustrate, um, uh, this is, this is essentially the ILO asic So, so the ILO ASIC is the, the gen 12 ASIC has changed to where we have dual core as, as Darren was talking about. We have a, there's 64 bit and there's a whole bunch of other stuff that, that these things have to where we think our two core, you know, solution is better than, uh, more, a lot more performant and and so on than, than the solutions that are out there, including the four core, you know, competitors.
'cause ours, ours is really optimized for this kind of stuff and do do things a lot faster. So anyway, so there's that, um, that, so think of this as the IO and this is a secure enclave within the IO So, so it is talking to, it is talking to, uh, the secure enclave, sorry, these arrows. It's talking to the secure enclave through these two buffers.
And then this is just a security perspective is that you cannot go outside, uh, you cannot go outside of the input buffer. This guy, it, it, the worst malware on earth could be running here. It can only access the secure enclave through here.
Like go give me your keys and stuff like that. It could do things like that. It can corrupt commands and all that.
But the secure enclaves gonna authenticate everything. It's gonna authenticate that and it's gonna authenticate the commands that are in there. So if you buffer overflow from one command into the next one, you just corrupted the next command.
Did you corrupt it in such a way that it will actually work? No. Uh, because it, 'cause each one is checked, each one has a, has a, um, you know, it has a, has a, a block, a security block on it.
Um, so that's how that works. That just trying to illustrate that it, it is truly secure. It's not only a secure processor.
There's a huge amount of stor, not huge for something like this, right? So it's, it's the size to keep as many keys that you could possibly need inside of the biggest of our server chassis. So, so Let's talk about, let's talk about the keys a little bit.
'cause you've, you know, your, your notes say you eliminated the, the, the external eprom, which means you can't, you know, put a chip on it, suck the data out, the eprom, right? Um, access A TPM for the security processor, which for ILO, which makes sense. Um, but you mentioned the use case of, okay, you wanna store your SED, your software encrypting drive keys in it, but then you wanna be able to back up and extract those keys.
So are you backing up those keys from the drive or through the tp, through the enclave and the TPM? I Dunno, do we have a slide on that? Yeah.
Okay. Um, let, let's just jump over. So the way works, I have A nice set of, So, so think of in this drawing here, so we have the ilo.
So think of, uh, uh, the OS and the, and the SCS all living up here. So the way it works is the, uh, the, the, the, the key, the, the path for the keys are from the SCS today, uh, into bios, and then bios sends it down to the IO. So once it gets to the IO, so, so a, a key request or keys going in the other direction, what happens is that ILO has a choice of doing one of, one of actually four things, or I should say three things.
One of 'em is, is later, but what it can do is it can say, okay, I want those keys stored within the secure enclave. Mm-hmm. Or using what we have today is I want it, uh, stored outside into one of these, uh, external HSMs, you know, like from taes and KO and so on, that we have, we have a path there.
So that's, that's, that's today. That's gen 11, right? So, so we didn't take that away.
That's still there. But the interesting case here is that I want 'em stored locally, but I want 'em backed up to one of these guys out here. Right.
So that's, that's what's different. And this is just, this is not just one server. This could be a cluster.
Yeah. Yeah. So it's, it's traditional key management, external key management with the ability to use ILO as a, uh, the, the secure enclave is a TPM for ILO itself as well.
Yeah. So you're familiar with Tais? Yeah.
Yeah. Okay. So we were showing off this stuff to them a couple weeks ago at our big sales event.
Mm-hmm. And we were breaking it down and he goes, huh, because as we talked about earlier, because of this design we did, we're able to compete for FIPs one 40 dash three level three. Right, right.
Which is significantly more difficult, but they were able to design to meet those standards. Okay. So he's hearing that and he's like, okay.
'cause they have HSMs and remote key managers that also meet FIPs one 40 dash three level three. Yeah. He goes, Cole, you have an HSM in your server.
We're like, well, we don't like to use that word. He goes, well, I don't care. You have an HSM because what you're able to do here for a customer is you take it from that FIPs one 40 dash three level three area of secure storage, and you pass the handoff to another FIPs one 40 dash three level three HSM.
So you're kind of keeping this higher level of data integrity. You don't have to drop down to something less secure and then over to a more secure, it is a HSM to HSM handoff is the way he was kind of articulating. And I was like, wow, I haven't really thought of it like that, but he is like, you should, That that was the thinking behind this.
So we had, we started with the use case, this is mm-hmm. Use case. We want to, we want to wanna meet.
And then, okay, how do we make it, uh, these guys are all, like Cole said, these are all level three, meaning that they have some strong protections against physical attacks. So we wanna do our solution also level three, so that no matter where the key is stored, you know, locally or backed up or however you wanna do that. Mm-hmm.
It's always in a level three. That's right. Right.
You're never stepping Back against physical attacks. So the customer, you know, we're talking about who, CIOs and all that, they don't have to worry about any of that. It's level three everywhere.
The, the memory in the secure enclave is volatile. Yeah. Volatile.
No, uh, well, some of it is obviously, so, so, you know, data and, uh, uh, but it has a non-volatile storage within it as well. That's where the keys are kept. Because what I'm, I'm thinking here is, uh, you know, I, I'm thinking about the paradigm of what data and motion data and use data at rest.
And I feel like, so the data at rest side, that's your key managers and it, it, I I feel like I'm compartmentalizing them. Maybe not correctly, but we're talking about data and use security here in IL That's Yeah. The keys, you mean keys, yeah.
Actively going back and forth between the SCDs and all In use Yeah. Data. Yeah, it's like data and use well data And be in transit through that path.
Mm-hmm. Right? We're talking about once it gets to the enclave, then it's data.
It's data at the keys at rest. Yeah. Yeah, Yeah.
So, so I don't, I don't your questions about Interest. Well, I mean that's, I think that's a a, you know, you, you, when it comes to a lot of elements of data security in particular, you know, you want, whether it's encryption or other sort forms of protection, access control, um, you wanna cover all three domains and use in rest and, and, and in motion. Yeah.
To protect in transit. That, I don't know if you've heard of the term Keck. So key encryption key.
Mm-hmm. So if someone steals it, oh, well, but it's, it's, it, the key itself is encrypted so that that's to protect it in transit. Mm-hmm.
Because I, the reason I'm thinking that this is, okay, so, you know, uh, uh, I have level three here. I have level three here. I what if some somebody, you know, pens my level three or, or you know, whatever it is, the data and rest part, you can't really control that.
But what you can control is the data. I'm thinking of it as data in use, but you keep talking about transit, maybe it's data use and data in motion. And that's pretty good coverage.
Yeah. We think, we think we do. And, and level three, I dunno if you mind me nerding out here for a little bit, but level three has things like side channel attack protection that we have in our asic for instance, like, like the random bit generator is within the secure enclave for, for, for, for all of this, right?
And then what if somebody cranks up the voltage just a little bit or lowers the voltage so that the random bit generator generates more ones than zeros, you know, stuff like that. So it has, it has protection against those kind of things. Like the voltage, the temperature clocks, you know, I start, you know, so that's a typical attack is to jack up the temperature or something like that.
Get it to crash. Oh, okay, we found it some bad things. Okay, let's bring it down and let's see how we can exploit this.
But that's, that's, uh, it's, it has trip wires as required by FIPs one 40 dash three level three to, to not let you go outta range on any of these things. And, and, and, and it's, it's not the normal trip wire, like a thermal trip. It's, it's much more sensitive than that.
It's like it, as soon as it's beyond its op, you know, normal, you know, balance between ones and zeros as much as possible, then trip, it's, it's, it's a, it, you're, you're booted out of FIPs mode. Go try again, try again, try again. Okay.
Something's permanently wrong, then you're out of FIPs mode permanently. Um, and, and there's a lot of stuff that happens when, when you're booted out of FIPs mode, for instance, all your critical security parameters get wiped. You know, it's assumed that the box has been compromised, is essentially the way they look at it.
So that's, we have all that stuff in there. So we talked about SPDM already, uh, uh, what's here? So it's just to show that it's, it's it's industry standard.
It's really as much as possible, we adhere to the standard, but there SPDM does a lot more than, than we may, we may need for some simple devices. So in some cases, you'll see it's not SPDM, it's really something more proprietary, you know, that that meets that, that, uh, you know, we only need it to do this. So, so, so we, so we do that rather than the full SPDM stack.
But anything that, that you would consider to be, you know, third party or anything like that, SPDM trying to drive the industry in that direction. Other, our competitors are trying to do, do the same thing. So we're gonna see more and more of that kind of stuff.
Um, and then, uh, this is just a, just a, a list of all the things that we do in gen 12 security wise. So I'll go through that very quickly. So we already talked about, uh, so, so introduce SPDM and Gen 11.
Uh, so introduce, uh, compute ops management com and then, uh, let's see, automated, let's see, is there anything here? Uh, we didn't talk about platform certificates and ID IDs, I don't know if you guys care about that, but that's really a platform certificate is, is an inventory. When we build a server, here's an inventory of everything.
It gets sent up here to this building to get signed, and then it goes back. It either goes to the customer through some independent channel or it's inside the box so that when you, when you, when your box arrives on the loading dock, you plug it in, you can verify that it has not been tampered with in transit. In other words, the inventory that was there when we shipped it is still right.
So that's, that's a, an industry standard way to do that. iDev, id, uh, I don't know if you've heard of this. It's, uh, it's, it cloud enables, especially, this is really interesting in cases of, uh, edge type type deployments.
In other words, uh, I'm a telco. I have my, you know, as a technician goes into the, the building that's at the base of the cell tower. They plug it in, right?
And, and, and, and it's okay. It's all hooked up to the network and all that. That's all they know about this stuff.
And they leave. So what good is that? Well, what happens is you can configure the server to go off and call your authentication.
What goes through the switch? The switch goes to a radius server, and, uh, uh, it authenticates. Is this, is this the box that I ordered that, that just showed up at the base of the cell tower?
Yes, it is. Okay. Now I open up the switch, I mean, to, to the, the, the port on the switch to do all the stuff, you know, now, now it has free access.
So at that point, I would kick off a deployment. We're outta time, uh, and so on. But that's, that's, ID dev ID is really intended for that kind of stuff.
And it's, uh, industry standard as well. We're done. Um, we're soldering down tpms.
And then, anyway, we started doing that kind of stuff. So in gen 12, we talked about that SPDM storage events. I mean, we get into, I this probably say the only thing that's probably in here is that it's not a one size fits all, right?
We hit some of these high bars that we're hearing a lot about FIPs and NIST and some of that. We use those accomplishments to hit that highest level of national security to then go apply to other industries that, uh, are valuing this and that we're seeing more and more, uh, you know, with transportation, logistics, telco, uh, even service providers.