Storage enclosure
By introducing locking mechanisms, authentication systems, and network isolation designs into the storage enclosure, the security and management efficiency issues of storage devices are solved, enabling secure storage and remote personalized configuration of the devices.
Patent Information
- Application Number
- CN201980098808.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-07-26
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2039-07-26
AI Technical Summary
Existing storage devices present security and management efficiency issues regarding unauthorized user access and device information updates, especially when remote storage is being accessed or devices are being changed.
The device employs a storage enclosure design that includes a locking mechanism, authentication system, logical configuration system, and hardware logic system. It achieves secure storage and instruction modification through RFID tags and firewalls, and utilizes B2B networks and image loaders for personalized device configuration.
It provides secure storage and remote management of devices, ensuring that only authorized users can access and update device information, thereby improving the security and management efficiency of storage devices.
Smart Images

Figure CN114127719B_ABST
Abstract
Description
Background Technology
[0001] Storage enclosures can be used to securely store devices from unauthorized users. For example, a storage enclosure may include a locker with storage areas and locking devices to prevent unauthorized access to those areas. In some examples, the storage enclosure can be used by a user to securely store devices when the user is located away from it. In other examples, the storage enclosure can be used to securely store devices provided by a first user, allowing a second user to retrieve the device from the enclosure. Attached Figure Description
[0002] Figure 1 This is an example system of a storage enclosure conforming to this disclosure.
[0003] Figure 2 This is an example system of a storage enclosure conforming to this disclosure.
[0004] Figure 3 This is an example system of a storage enclosure conforming to this disclosure.
[0005] Figure 4 This is an example system of a storage enclosure conforming to this disclosure. Detailed Implementation
[0006] In some examples, a storage enclosure can be used to securely store devices. For example, the storage enclosure may include a locking mechanism to prevent unauthorized access to devices within the enclosure. In some examples, the locking mechanism may include an authentication system to authorize a user before unlocking or granting access to the storage area of the storage enclosure. For example, the locking mechanism may be activated or in a locked position to prevent access to the storage area of the storage enclosure. In this example, the locking mechanism may be coupled to an authentication system to receive authentication information (e.g., a personal identification number (PIN), badge, etc.) to authenticate the user. In this example, when the authentication information is determined to be from an authorized user, the locking mechanism may be switched to a deactivated or unlocked position.
[0007] This disclosure relates to storage enclosures that can be used to store computing devices (e.g., desktop computers, laptop computers, cellular phones, tablet computers, etc.) or other types of devices. In some examples, the device can be updated or modified while stored within the storage enclosure. For example, the storage enclosure may include a first network that can be used to modify the instructions or characteristics of the device while it is stored within the enclosure. In this example, the first network can be used to modify instructions or personalize the computing device stored within the storage enclosure, and a second network can be used to control and / or manage the storage enclosure. In this example, a firewall can be used to block communication between the first and second networks and / or manage communication between them. In this way, the first network can provide access to a first group of authorized users, and the second network can provide access to a second group of authorized users. The storage enclosure described herein can provide a secure physical location for storing computing devices and secure network connectivity for allowing authorized users to modify instructions and / or personalize the computing device stored within the storage enclosure.
[0008] The figures in this document follow a numbering convention, where the first number corresponds to the figure number, and the remaining numbers identify the elements or components in the figures. Elements shown in the various figures of this document may be added, interchanged, and / or eliminated to provide multiple additional examples of this disclosure. Furthermore, the scale and relative scaling of the elements provided in the figures are intended to illustrate examples of this disclosure and should not be considered in a limiting sense.
[0009] Figure 1 This is an example system 100 for a storage enclosure 102 conforming to this disclosure. System 100 may include a storage enclosure 102, which may include a storage area 104 to physically enclose or store a device 106 within the storage area 104. In some examples, when a locking system 108 is activated or in a locked state, the storage enclosure 102 may utilize the locking system 108 to lock the device 106 within the storage area 104 or prevent access to it.
[0010] In some examples, storage housing 102 may be a storage room and / or locker having multiple storage areas similar to storage area 104. For example, storage housing 102 may be a housing or room comprising multiple separate housings or storage areas, each housing or storage area being used to securely store a device (e.g., device 106, etc.). As further described herein, when device 106 is within storage area 104 of storage housing 102, storage housing 102 may be used to securely store and modify instructions for device 106.
[0011] In some examples, system 100 may include a logical configuration system 110, which may include instructions for identifying device 106 within storage area 104 and instructions for changing the association of device 106 within storage area 104. In some examples, logical configuration system 110 may be communicatively coupled to device 106 via communication path 134. For example, logical configuration system 110 may be coupled to device 106 via an Ethernet connection, local area network (LAN), and / or other types of communication paths. In this way, logical configuration system 110 can be used to communicate with device 106 when device 106 is located within storage area 104 of storage housing 102.
[0012] In some examples, the logical configuration system 110 may be coupled to the device 106 when the device 106 is located within the storage area 104 of the housing 102. For example, a user may place the device 106 within the storage area 104 and connect it to the communication path 134 before locking the device 106 within the storage area 104 using the locking system 108. In this example, the logical configuration system 110 may be used to change instructions for the device 106, including when the device 106 is locked within the storage area 104. As used herein, instructions to change the device 106 may include changes to the device 106's software, firmware, and / or instructions (e.g., machine-readable instructions, etc.). That is, instructions to change the device 106 may include update instructions, firmware change instructions, download device images, and / or other types of changes that can be performed via the communication path 134.
[0013] In some examples, when device 106 is located within storage region 104, logical configuration system 110 can be used to determine the device type and / or unique identifier of device 106. For example, logical configuration system 110 can be used to determine the serial number of device 106, determine the media access channel (MAC) address associated with device 106, and / or other information associated with device 106. In some examples, logical configuration system 110 can utilize first device identification system 114 to retrieve the device type and / or unique identifier of device 106.
[0014] In some examples, system 100 may include a first device identification system 114, which can be used to determine the device type and / or unique identifier of device 106 when device 106 is located within storage area 104. For example, the first device identification system 114 may include a radio frequency identification (RFID) reader to extract device type, unique identifier, MAC address, network information, power status, power supply, and / or other information associated with device 106 from an RFID tag associated with device 106. For example, device 106 may include a passive RFID tag with device information (e.g., device type, unique identifier, MAC address, network connection status, power connection status, etc.) stored on the passive RFID tag. In this example, a manufacturer or organization may store information on a passive RFID tag and install the passive RFID tag on or within device 106.
[0015] In other examples, device 106 may include a dynamic RFID tag. As used herein, a dynamic RFID tag may be an RFID memory resource that stores current or latest device information by device 106 while device 106 is operating. In this way, even if the device information has been changed during the operation of device 106, the dynamic RFID tag may still include current device information (e.g., MAC address, unique identifier, network status, power status, correctly connected to power, correctly connected to a network, etc.). For example, device 106 may change its network status during operation and update the dynamic RFID tag with the updated network status. As used herein, network status or network connection status may be an indication of whether device 106 is connected to a network (e.g., LAN, WAN, cellular network, etc.). Similarly, a dynamic RFID tag may include updated power status or power connection status. As used herein, power connection status may include an indication of whether device 106 is connected to a power source (e.g., mains power, remote battery, etc.). In this way, when device 106 is located within storage area 104, the dynamic RFID tag may include updated device information for device 106. In contrast, passive RFID tags may include outdated or incorrect device information related to device 106.
[0016] In some examples, system 100 may include a locking system 108 to lock and unlock storage area 104 of storage housing 102. For example, locking system 108 may include multiple locking devices that can be used to lock doors or windows providing access to storage area 104. In this way, locking system 108 can be used to activate specific locking devices to lock a corresponding storage area (e.g., storage area 104, etc.) to prevent unauthorized access to devices within the corresponding storage area and / or deactivate specific locking devices to unlock the corresponding storage area to allow access to the corresponding storage area.
[0017] In some examples, system 100 may include hardware logic system 112 to control and / or communicate with locking system 108. For example, hardware logic system 112 may be communicatively coupled to locking system 108 via communication path 138. In some examples, hardware logic system 112 may include instructions for activating and / or deactivating locking devices of locking system 108. In some examples, hardware logic system 112 may include instructions for determining device information of device 106 located within a specific storage area 104. As described herein, system 100 may include a second device identification system 116 to extract device information extracted by first device identification system 114. Device information may be provided to hardware logic system 112. In some examples, second device identification system 116 may include an RFID reader to extract device information stored on an RFID tag associated with device 106 in a manner similar to first identification system 114. In some examples, first identification system 114 and / or second device identification system 116 may be located within storage area 104 and / or within readable range of device 106. As used herein, the readable range of device 106 can be the distance between an RFID tag and an RFID reader, where the RFID reader can extract data (e.g., device information, etc.) from the RFID tag. In some examples, the first identification system 114 may be located within storage area 104, and the second identification system 116 may be located outside storage area 104. In these examples, the second identification system 116 may be within the readable range of device 106. In this way, interference between the first identification system 114 and the second identification system 116 can be reduced or eliminated.
[0018] In some examples, hardware logic system 112 may use device information to determine whether to activate or deactivate the locking device of locking system 108. For example, device 106 may be located within storage area 104 and coupled to communication path 134. In this example, device information of device 106 may be provided to hardware logic system 112, as further described herein, and hardware logic system 112 may determine whether device 106 is located in the correct or designated storage area 104. In this example, hardware logic system 112 may be used to instruct locking system 108 to lock storage area 104 when device 106 is located within storage area 104 or when device 106 is designated to be located within storage area 104. In some examples, hardware logic system 112 may be used to instruct locking system 108 to lock storage area 104 when device 108 is directly connected to power, communication path 134, and / or is near device identification system 114 when device identification system 114 is an RFID reader. In some examples, a specific storage area may be designated to receive a specific device. For example, an organization can designate a specific storage area to receive the corresponding device from a user to ensure that the correct device is delivered before a different device is provided to the user. In this example, hardware logic system 112 can be used to ensure that the correct device is powered and / or connected in the corresponding storage area of storage housing 102.
[0019] In some examples, system 100 may include firewall 130 to prevent direct communication between logical configuration system 110 and hardware logic system 112. In some examples, logical configuration system 110 may utilize a first network (e.g., communication path 134, communication path 136, etc.) and hardware logic system 112 may utilize a second network separated by firewall 130 (e.g., communication path 138, communication path 140, etc.). In this way, direct communication between logical configuration system 110 and hardware logic system 112 can be prevented. As used herein, firewall 130 may include a computing system to block unauthorized access to a network or device while allowing outward communication from the network or device.
[0020] In some examples, the logical configuration system 110 may communicate with the logical management system 128 via a first network and / or communication path 136. The logical management system 128 may be used to manage the logical configuration system 110. For example, the logical management system 128 may provide instructions to the logical configuration system 110 for changing devices 106 within storage area 104 and / or other devices located within storage enclosure 102. In a similar manner, the hardware logic system 112 may communicate with the hardware management system 126 via a second network and / or communication path 140. In a similar manner, the hardware management system 126 may manage the hardware logic system 112 by providing instructions to it.
[0021] In some examples, the logical management system can be communicatively coupled to the hardware management system 126 via communication path 132. In some examples, communication path 132 can be a secure communication path. As used herein, a secure communication path can utilize encryption or other technologies to securely transmit communication between multiple devices. For example, the logical management system 128 can send encrypted communication to the hardware management system 126, and the hardware management system 126 can send encrypted communication to the logical management system 128 via communication path 132. In another example, firewall 130 can be used to selectively allow communication through communication path 132 to allow communication between the hardware management system 126 and the logical management system 128. For example, communication path 132 can be specifically opened for communication between the hardware management system 126 and the logical management system 128. In this way, the logical management system 128 can communicate directly with the hardware management system 126 without compromising the firewall 130 between the first and second networks.
[0022] As described herein, when device 106 is located within storage area 104, device information associated with device 106 can be extracted by the first device identification system 114. In some examples, the first identification system 114 can provide the device information to the logical configuration system 110, and the logical configuration system 110 can provide the device information to the logical management system 128 via a first network and / or communication path 136. In these examples, the logical management system 128 can provide the device information to the hardware management system 126 via a secure communication path 132, and to the hardware logic system 112 or the second device identification system 116 via a second network and / or communication path 140. In this way, device information can be extracted from device 106 and provided to the hardware logic system 112 for use as described herein.
[0023] In some examples, the first device identification system 114 may utilize the status publishing system 111 to publish device information. As used herein, the status publishing system 111 may include memory resources to allow storage or writing of data, such as device information. In some examples, the status publishing system 111 may provide device information or other data stored in memory resources to the status reading system 113. As used herein, the status reading system 113 may include memory resources capable of storing data to be read, such as device information. In some examples, the hardware logic system 112 may read data stored on the status reading system 113 to determine device information for device 106.
[0024] In some examples, a first network (e.g., communication path 134, communication path 136, etc.) may be used to provide access to a logical user 142 associated with instructions to change device 106 located within storage area 104. For example, logical user 142 may include a local information technology (IT) administrator, a remote end-user of device 106, and / or a remote IT administrator. In some examples, a second network (e.g., communication path 138, communication path 140, etc.) may be used to provide access to a hardware user 144 associated with operating and maintaining locking system 108. For example, hardware user 144 may include a local logical administrator and / or a remote logical administrator.
[0025] In some examples, system 100 may include a logical user authentication system 118 and a hardware user authentication system 120 to allow a user 122, physically located or remote from storage enclosure 102, to access the corresponding system (e.g., logical configuration system 110, hardware logical system 112, etc.). For example, user 122 may provide credentials to logical user authentication system 118 to access logical configuration system 110 and / or storage area 104, thereby accessing device 106 and / or locating device 106 within storage area 104. In similar examples, user 122 may provide credentials to hardware user authentication system 120 to obtain access to hardware logical system 112 and / or locking system 108. In these examples, the correct credentials provided to logical user authentication system 118 for access may differ from the correct credentials provided to hardware user authentication system 120 for access. In some examples, firewall 130 may block communication between hardware user authentication system 120 and logical user authentication system 118. In this way, the first group of users can be authorized to the logical authentication system 118, and the second group of users can be authorized to the hardware user authentication system 120. This increases the security of system 100. In some examples, users can be part of both the first and second groups of users.
[0026] System 100 can provide secure storage for devices such as device 106. Furthermore, while device 106 is within storage area 104, system 100 can provide a secure location to modify instructions associated with device 106. In this way, device 106 can be securely stored within storage area 104 and updated or modified via logical configuration system 110, including while the device is stored in storage area 104. In this way, an organization can allow devices such as device 106 to be placed down by users and different devices to be picked up by users without the risk of devices being stolen or modified by unauthorized users. Furthermore, system 100 allows users to modify or update device 106 while it is within storage area 104 before picking it up from storage area 104. In this way, users can personalize device 106 and / or delegate the personalization of device 106 before picking it up from storage area 104.
[0027] Figure 2 This is an example system 200 for a storage housing 202 that conforms to this disclosure. In some examples, system 200 may include, for example, Figure 1 The referenced components are the same as or similar to those in system 100. For example, system 200 may include a storage housing 202 that can store multiple devices 206-1, 206-2, 206-3, 206-N within a storage area and / or multiple corresponding storage areas. Furthermore, system 200 may include a logic management system 228 and a hardware management system 226. In some examples, the logic management system 228 may be communicatively coupled to the multiple devices 206-1, 206-2, 206-3, 206-N via a first network 236, and the hardware management system 226 may be communicatively coupled to a locking mechanism and / or device identification devices 260-1, 260-2, 260-3, 260-N via a second network 240.
[0028] As described herein, the first network 236 may be different from and / or separate from the second network 240. For example, the first network 236 may be accessible through a firewall (e.g., as...). Figure 1 The firewall 130 (as referenced in the text) is separate from the second network 240. In some examples, the first network 236 and the second network 240 can be separate networks that operate independently. In other examples, the first network 236 and the second network 240 can be shared networks or hybrid networks, such that access to one network allows access to the other network when security between the logical management system 228 and the hardware management system 226 is not an issue.
[0029] In some examples, multiple devices 206-1, 206-2, 206-3, 206-N may include corresponding network connections 256-1, 256-2, 256-3, 256-N. As used herein, a network connection can be a device capable of connecting to a network. For example, network connections 256-1, 256-2, 256-3, 256-N can be Ethernet ports, wireless network controllers, and / or other types of connections to communicatively couple multiple devices 206-1, 206-2, 206-3, 206-N to a first network 236 and / or a logical management system 228. In some examples, devices from multiple devices 206-1, 206-2, 206-3, 206-N may be positioned within storage housing 202 before locking storage housing 202 and / or corresponding storage areas, and communicatively coupled to the first network 236 and / or the logical management system 228.
[0030] For example, the first device 206-1 may be located within storage enclosure 202. In this example, the first network connection 256-1 of the first device 206-1 may be coupled to a first network 236 and / or a logical management system 228. In this example, the logical management system 228 may confirm that the first device 206-1 is communicatively coupled and located within storage enclosure 202. In this example, the logical management system 228 may utilize a business-to-business (B2B) network 252 to notify the hardware management system 226 that the first device 206-1 is located within storage enclosure 202 and communicatively coupled to the logical management system 228. In this example, the hardware management system 226 may, in response to receiving an instruction that the first device 206-1 is located within storage enclosure 202 and communicatively coupled to the first network 236 and / or the logical management system 228, lock the corresponding storage area of the first device 206-1 and / or lock storage enclosure 202. As used herein, the B2B network 252 may be a network in which a first enterprise and a second enterprise exchange information.
[0031] In some examples, the hardware management system 226 can extract device information from multiple devices 206-1, 206-2, 206-3, and 206-N. As described herein, the device information may include details associated with the multiple devices 206-1, 206-2, 206-3, and 206-N. For example, the device information may include unique identifiers (e.g., serial numbers, model numbers, etc.) of the multiple devices 206-1, 206-2, 206-3, and 206-N, MAC addresses associated with the multiple devices 206-1, 206-2, 206-3, and 206-N, and / or other information associated with the multiple devices 206-1, 206-2, 206-3, and 206-N.
[0032] In some examples, device information may be stored on corresponding memory resources of multiple devices 206-1, 206-2, 206-3, 206-N. For example, the multiple devices 206-1, 206-2, 206-3, 206-N may include corresponding RFID tags 258-1, 258-2, 258-3, 258-N. As described herein, the RFID tags may include memory resources coupled to a radio frequency device. For example, the multiple RFID tags 258-1, 258-2, 258-3, 258-N may include memory resources for storing device information and radio frequency transmitters for transmitting the stored device information to an RFID reader. In some examples, the multiple RFID tags 258-1, 258-2, 258-3, 258-N may include excitation coils that can receive radio frequency waves to generate power for the RFID transmitter. In these examples, the RFID reader can provide radio frequency waves to the excitation coil, and multiple RFID tags 258-1, 258-2, 258-3, and 258-N can transmit corresponding device information to the RFID reader in response to the excitation coil receiving the radio frequency waves.
[0033] In some examples, multiple RFID tags 258-1, 258-2, 258-3, and 258-N may be passive RFID tags. As used herein, passive RFID tags may include memory resources containing static device information. Device information can be static when it is not updated by the corresponding device during operation of the corresponding device. In other examples, multiple RFID tags 258-1, 258-2, 258-3, and 258-N may be dynamic RFID tags. As used herein, dynamic RFID tags may include memory resources that are actively updated by the device having device information (e.g., periodically, during setup, etc.). As described herein, dynamic RFID tags can be updated by the device during operation. For example, device 206-1 may include an active RFID tag 258-1. In this example, device 206-1 may check the accuracy of the data stored on RFID tag 258-1 and determine whether the data needs to be changed or updated based on a comparison of the data with the current state of the device. If the data is outdated or incorrect, device 206-1 may change the information stored on RFID tag 258-1. In this way, when RFID tag 258-1 is an active RFID tag, the device information stored on RFID tag 258-1 can be identified as the current device information of device 206-1.
[0034] In some examples, system 200 may include multiple device identification devices 260-1, 260-2, 260-3, 260-N communicatively coupled to hardware management system 226 via a second network 240. In some examples, the multiple device identification devices 260-1, 260-2, 260-3, 260-N may include RFID readers to extract device information from multiple RFID tags 258-1, 258-2, 258-3, 258-N. As described herein, in addition to other information associated with the multiple devices 206-1, 206-2, 206-3, 206-N, the device information may also include a serial number, MAC address, and model number. In some examples, hardware management system 226 may activate or deactivate a locking system or lock devices based on the device information. For example, a specific storage area may be prepared for a specific device from the multiple devices 206-1, 206-2, 206-3, 206-N. In this example, the hardware management system 226 can use device information to confirm that the correct device is located, powered, and / or communicatively connected to the correct storage area. In other examples, the hardware management system 226 can use the B2B network 252 to transmit device information to the logical management system 228.
[0035] In some examples, system 200 may include an image loader 254. In some examples, image loader 254 may be a configuration device used to load device images onto multiple devices 206-1, 206-2, 206-3, 206-N. In some examples, image loader 254 may include multiple device images that may correspond to multiple different users. For example, a first user may utilize a first device image, and a second user may utilize a second device image. In this example, the first device image may include a first set of settings, preferences, and / or applications to be applied to a particular device, and the second device image may include a second set of settings, preferences, and / or applications to be applied to a particular device. In this example, image loader 254 may apply the first device image to a first device 206-1 corresponding to a first user, and apply the second device image to a second device 206-2 corresponding to a second user. In this way, each of the multiple devices 206-1, 206-2, 206-3, 206-N can be uniquely configured for a specific user of the device.
[0036] In some examples, image loader 254 may include a Wake-on-LAN (WOL) function. As used herein, the WOL function may allow image loader 254 or other devices to activate multiple devices 206-1, 206-2, 206-3, 206-N and perform functions (e.g., provide device images, etc.) on these devices. In these examples, image loader 254 and the multiple devices 206-1, 206-2, 206-3, 206-N may be communicatively coupled to a first network 236. In this way, first device 206-1 can be activated from a deactivated or off state, enabling image loader 254 to download a specific device image to first device 206-1. In this example, once the specific device image is installed on first device 206-1, image loader 254 can deactivate first device 206-1. This allows the first device 206-1 to include specific user settings, preferences, and / or applications before the user picks up the device from the storage housing 202.
[0037] In some examples, system 200 may include a logical user authentication system 218 and a hardware user authentication system 220 to allow users physically located or far from storage enclosure 202 to access the respective system. For example, a user who picks up first device 206-1 and puts down second device 206-2 can provide credentials to logical user authentication system 218. When authorized, the user can unlock first device 206-1 from the storage area and lock second device 206-2 within the storage area. In this way, a user can replace second device 206-2 with first device 206-1 without having to configure first device 206-1, because first device 206-1 can have a specific device image loaded before the user puts down second device 206-2. Furthermore, the user does not need to change the settings of second device 206-2 before putting it down, because image loader 254 can change the instructions of second device 206-2 as second device 206-2 is communicatively coupled to first network 236, as described herein.
[0038] System 200 can provide secure storage for devices such as multiple devices 206-1, 206-2, 206-3, and 206-N. Furthermore, system 200 can provide a secure location to modify instructions associated with multiple devices 206-1, 206-2, 206-3, and 206-N while they are stored within storage housing 202. In this way, multiple devices 206-1, 206-2, 206-3, and 206-N can be securely stored within storage housing 202 and can be updated or modified while they are stored within storage housing 202. Additionally, system 200 allows a user to modify or update devices while they are within storage housing 202 before removing them from storage housing 202. In this way, users can personalize their devices before taking them out of the storage case.
[0039] Figure 3 This is an example system 300 for a storage housing 302 that conforms to this disclosure. In some examples, system 300 may include, for example, Figure 1 The system 100 and / or such referenced in the document Figure 2 The system may use the same or similar components as system 200. For example, system 300 may include a storage housing 302 that can store multiple devices 306-1, 306-2, 306-3, 306-N within a storage area and / or multiple corresponding storage areas. Furthermore, system 300 may include a logic management system 328 and a hardware management system 326. In some examples, the logic management system 328 may be communicatively coupled to the multiple devices 306-1, 306-2, 306-3, 306-N via a first network 336, and the hardware management system 326 may be communicatively coupled to a locking mechanism via a second network 340.
[0040] As described herein, the first network 336 may be different from and / or separate from the second network 340. For example, the first network 336 may be accessible through a firewall (e.g., as...). Figure 1 The firewall 130 (as referenced in the text) is separate from the second network 340. In some examples, the first network 336 and the second network 340 can be separate networks that operate independently. In other examples, the first network 336 and the second network 340 can be shared networks or hybrid networks, such that access to one network allows access to the other network when security between the logical management system 328 and the hardware management system 326 is not an issue.
[0041] In some examples, multiple devices 306-1, 306-2, 306-3, 306-N may include corresponding network connections 356-1, 356-2, 356-3, 356-N. As described herein, a network connection can be a device capable of connecting to a network. For example, network connections 356-1, 356-2, 356-3, 356-N can be Ethernet ports, wireless network controllers, and / or other types of connections to communicatively couple multiple devices 306-1, 306-2, 306-3, 306-N to a first network 336 and / or a logical management system 328. In some examples, devices from multiple devices 306-1, 306-2, 306-3, 306-N may be positioned within storage housing 302 before locking storage housing 302 and / or corresponding storage areas, and communicatively coupled to the first network 336 and / or the logical management system 328.
[0042] In some examples, the logic management system 328 and / or the hardware management system 326 can utilize device information of multiple devices 306-1, 306-2, 306-3, and 306-N. For example, the logic management system 328 can use the unique identifiers and / or MAC addresses of the multiple devices 306-1, 306-2, 306-3, and 306-N to modify instructions associated with the multiple devices 306-1, 306-2, 306-3, and 306-N. In other examples, the hardware management system 326 can use the device information to confirm that a specific device is stored in a specific storage area of the storage housing 302. In some examples, the hardware management system 326 can determine whether to lock or unlock a specific storage area based on the device information. In these examples, a specific user may want to access a specific storage area, and the hardware management system 326 can confirm that the corresponding device is located in the specific storage area before unlocking the specific storage area for the user. B2
[0043] In some examples, system 300 may include database 362, which may be used to store device information for multiple devices 306-1, 306-2, 306-3, 306-N and / or other devices. In some examples, database 362 may include unique identifiers, serial numbers, MAC addresses and / or other device information for multiple devices 306-1, 306-2, 306-3, 306-N. In some examples, the database may be communicatively coupled to logical management system 328 via a first communication path 364 and communicatively coupled to hardware management system 326 via a second communication path 366. In some examples, the first communication path 364 may be decoupled from the second communication path 366. For example, as described herein, the first communication path 364 and the second communication path 366 may be decoupled via a firewall. In this way, logical management system 328 and hardware management system 326 may each securely access device information for a specific device stored within storage housing 302.
[0044] In some examples, the logic management system 328 and the hardware management system 326 can communicate via a B2B network 352. For example, the logic management system 328 can determine the location or storage area of a specific device from multiple devices 306-1, 306-2, 306-3, and 306-N. In this example, the logic management system 328 can request device information for a specific device from a database 362. In this example, the logic management system 328 can provide the hardware management system 326 with the storage location of a specific device, and the hardware management system 326 can request device information for a specific device from the database 362. As described herein, the hardware management system 326 can use the storage location and / or device information of a specific device to determine whether to lock or unlock a specific storage area of the storage enclosure 302.
[0045] In some examples, system 300 may include an image loader 354. As described herein, image loader 354 may be a configured device for loading device images onto multiple devices 306-1, 306-2, 306-3, 306-N. In some examples, image loader 354 may include multiple device images that may correspond to multiple different users. For example, a first user may utilize a first device image, and a second user may utilize a second device image. As described herein, image loader 354 may include WOL functionality. As described herein, system 300 may include a logical user authentication system 318 and a hardware user authentication system 320 to allow local users physically located for storage enclosure 302 to obtain access to the corresponding system.
[0046] System 300 can provide secure storage for devices such as multiple devices 306-1, 306-2, 306-3, and 306-N. Furthermore, system 300 can provide a secure location to modify instructions associated with multiple devices 306-1, 306-2, 306-3, and 306-N while they are stored within storage housing 302. In this way, multiple devices 306-1, 306-2, 306-3, and 306-N can be securely stored within storage housing 302 and updated or modified while they are stored within storage housing 302.
[0047] Figure 4 This is an example system 400 for a storage housing 402 that conforms to this disclosure. In some examples, system 400 may include, for example, Figure 1 The system 100 referenced in the text, such as Figure 2 The system 200 and / or such referenced in the document Figure 3 The system may contain the same or similar components as system 300. For example, system 400 may include a storage housing 402 that can store multiple devices within storage area 404 and / or multiple corresponding storage areas.
[0048] System 400 may include a first computing device 410 and a second computing device 412. In some examples, the first computing device 410 may be used as a logical configuration system (e.g., such as...). Figure 1 The logical configuration system 110 (as referenced in the text) and the second computing device 412 can be used as a hardware logic system (e.g., such as...). Figure 1 (Hardware logic system 112, etc., referenced herein). In some examples, the first computing device 410 and the second computing device 412 may include corresponding memory resources 474-1, 474-2 corresponding to processing resources 472-1, 472-2 and / or storing instructions to perform a specific function. Processing resources as used herein may include multiple processing resources capable of executing instructions stored in memory resources. Instructions (e.g., machine-readable instructions (MRI)) may include instructions stored on memory resources and executable by processing resources to perform a specific function. Memory resources as used herein may include multiple memory components capable of storing non-transitory instructions executable by processing resources.
[0049] Memory resources can communicate with processing resources via a communication link (e.g., a path). The communication link can be local or remote for the electronic device associated with the processing resource. Memory resource 474-1 includes instructions 476, 478, and 480, and memory resource 474-2 includes instructions 482, 484, and 486. Memory resources 474-1 and 474-2 can include more or fewer instructions than illustrated to perform the various functions described herein. In some examples, among other possibilities, instructions (e.g., software, firmware, etc.) can also be downloaded and stored in memory resources (e.g., MRM) and hard-wired programs (e.g., logic). In other examples, computing devices 410 and 412 can be hardware such as application-specific integrated circuits (ASICs), which can include instructions for performing specific functions.
[0050] The first computing device 410 may include instructions 476, which, when executed by processing resource 472-1, can identify a device within storage area 404 of storage housing 402. As described herein, the first computing device 410 can identify a device within storage area 404 using device information associated with the device. In some examples, the device may include a passive or dynamic RFID tag, which can allow the first computing device 410 to retrieve device information using an RFID reader device.
[0051] The first computing device 410 may include instructions 478, which, when executed by processing resource 472-1, can modify instructions associated with a device within storage area 404 of storage housing 402. As described herein, modifying instructions associated with a device may include changing device settings, updating device instructions or firmware, and / or downloading a device image to the device. As described herein, modifying instructions associated with a device may include personalizing the device for a specific user by changing specific instructions of the device based on user preferences.
[0052] The first computing device 410 may include instructions 480, which, when executed by processing resource 472-1, may upload a device image to the computing device based on a user associated with the computing device. As described herein, a device image may be a set of instructions used to provide specific settings, preferences, and / or applications to a specific device. The device image can be applied to make it easier for a specific user to utilize the device.
[0053] The second computing device 412 may include instructions 482, which, when executed by processing resources 472-2, can manage the hardware logic system of the storage chassis 402. In some examples, managing the hardware logic system may include instructions for providing device information to the hardware logic system, instructing the hardware logic system to activate or deactivate specific locking mechanisms, and / or authenticating users attempting to access the hardware logic system. In some examples, this functionality may be performed by a hardware management system as described herein.
[0054] The second computing device 412 may include instructions 484, which, when executed by processing resource 472-2, can activate and deactivate a locking mechanism of storage region 404 of storage housing 402. As described herein, the second computing device 412 may be communicatively coupled to the locking mechanism of storage region 404 and / or storage housing 402. In some examples, the second computing device 412 may activate and / or deactivate the locking mechanism based on device information. For example, the second computing device 412 may deactivate the locking mechanism to allow an authorized user to access a specific storage region 404. In this example, the second computing device 412 may activate the locking mechanism when an authorized user places an authorized device within storage region 404.
[0055] The second computing device 412 may include instructions 486, which, when executed by processing resource 472-2, can determine a unique identifier and media access control (MAC) address of the computing device within storage area 404 of storage housing 402. As described herein, device information for a device such as a computing device may include the computing device's MAC address and unique identifier. In this way, the second computing device 412 can determine the computing device's unique identifier and / or MAC address based on device information that can be extracted from an RFID tag associated with the computing device stored within storage area 404 of storage housing 402.
[0056] System 400 can provide secure storage for devices such as computing devices. Furthermore, system 400 can provide a secure location to modify instructions associated with multiple devices while they are stored within storage housing 402. In this way, multiple devices can be securely stored within storage area 404 of storage housing 402 and can be updated or modified while they are stored within storage housing 402.
[0057] The foregoing description, examples, and data provide a description of the methods, applications, and uses of the systems and methods of this disclosure. Because many examples can be made without departing from the spirit and scope of the systems and methods of this disclosure, this specification only illustrates a few of the many possible example configurations and implementations.
Claims
1. A physical storage enclosure, comprising: a locking mechanism to prevent removal of a device from a storage area; a logic configuration system coupled to a device at the storage area through a first network, wherein the logic configuration system includes instructions to identify the device at the storage area and to alter instructions associated with the device at the storage area; a hardware logic system coupled to the locking mechanism through a second network to activate and deactivate the locking mechanism; and a firewall separating the first network from the second network to limit communication between the logic configuration system and the hardware logic system. The hardware logic system includes a first authentication system to authenticate a user attempting to access the hardware logic system, and the logic configuration system includes a second authentication system to authenticate a user attempting to access the logic configuration system.
2. The physical storage chassis of claim 1, wherein, The firewall limits communication between the first authentication system and the second authentication system.
3. The physical storage chassis of claim 2, wherein, 4. A system, comprising: an enclosure to house a computing device and store the computing device within the enclosure; a locking mechanism coupled to lock the enclosure when the locking mechanism is activated; a logic configuration system coupled to the computing device within the enclosure through a first network to alter instructions associated with the computing device within the enclosure; a logic management system to manage the logic configuration system and a plurality of additional logic configuration systems; a hardware logic system coupled to the locking mechanism through a second network to activate and deactivate the locking mechanism; a hardware management system communicatively coupled to the logic management system through a secure communication path to manage the hardware logic system and a plurality of additional hardware logic systems; and a firewall separating the first network from the second network and selectively permitting communication through the secure communication path to limit communication between the logic configuration system and the hardware logic system and to permit communication between the logic management system and the hardware management system.
5. The system of claim 4, wherein the logic configuration system is coupled to the logic management system through a first network connection, and wherein the hardware logic system is coupled to the hardware management system through a second network connection.
6. The system of claim 4, wherein the logic management system provides an identification of the computing device to the hardware management system through the firewall.
7. The system of claim 4, wherein the logic configuration system includes instructions to determine a unique identifier and a media access control address of the computing device within the enclosure.
8. The system of claim 4, comprising an identification system to retrieve a network connection status and a power connection status of the computing device from a dynamic radio frequency tag of the computing device, wherein the dynamic radio frequency tag is updated by the computing device with the network connection status and the power connection status when the computing device is activated.
9. The system of claim 8, wherein the identification system includes an RFID reader located within a readable range of the enclosure to retrieve the unique identifier and the media access control address from the dynamic radio frequency tag.
10. A computing device storage enclosure, comprising: an enclosure to store a computing device within the enclosure; a locking mechanism coupled to lock the enclosure when the locking mechanism is activated; a device identification system to determine a unique identifier of the computing device located within the enclosure; and a logic configuration system coupled to the computing device within the enclosure through a first network to alter instructions associated with the computing device within the enclosure. a logic configuration system, coupled to the computing device within the enclosure over a first network, to alter instructions associated with the computing device within the enclosure based on a unique identifier of the computing device located within the enclosure; a status publishing system to receive status updates of the altered instructions executed by the logic configuration system and to receive the unique identifier of the computing device; a status reading system to receive status updates of the altered instructions executed by the logic configuration system and to receive the unique identifier of the computing device; a hardware logic system, coupled to the locking mechanism over a second network, to activate and deactivate the locking mechanism based on the unique identifier received from the hardware publishing system; and a firewall separating the first network from the second network to limit communication between the logic configuration system and the hardware logic system. The logic configuration system includes instructions to upload a device image to the computing device based on a user associated with the computing device.
11. The computing device storage chassis of claim 10, wherein, The first network includes a first authentication system to provide access to the first network, and the second network includes a second authentication system to provide access to the second network.
12. The computing device storage chassis of claim 10, wherein,
Citation Information
Patent Citations
Extending user authentication across a trust group of smart devices
CN105794244A
Data storage system comprising an array of drives
US20180357141A1