Methods to activate multiple edge servers

By establishing a trusted dialogue between an edge server and a designated website, obtaining activation rights, and activating other edge servers, the problem of activating multiple edge servers in existing technologies is solved, achieving rapid and automated activation.

CN115604259BActive Publication Date: 2025-12-02LENOVO (BEIJING) LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211065882.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-31
Publication Date
2025-12-02
Estimated Expiration
2042-08-31

AI Technical Summary

Technical Problem

The process of activating multiple edge servers in the existing technology is cumbersome and time-consuming, especially at edge sites that cannot be directly connected to the Internet. They need to be activated manually or through a mobile application one by one, resulting in low efficiency.

Method used

By establishing a trusted dialogue on an edge server, using that server to connect to a designated website to obtain activation rights, and then using those rights to activate other edge servers, the automated activation of multiple edge servers can be achieved.

Benefits of technology

It enables rapid and automated activation of multiple edge servers, reducing manual intervention and time consumption, and improving activation efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115604259B_ABST
    Figure CN115604259B_ABST
Patent Text Reader

Abstract

A method for activating a first edge server (10a) and a second edge server (10b, 10c, 10d) is disclosed, wherein the first edge server includes a first service processor (14a), and each of the second edge servers includes a second service processor (14b, 14c, 14d). The method includes connecting the first service processor and the second service processor in a data-interoperable manner, connecting the first service processor in a data-interoperable manner with a designated website (18) through a mobile phone application (100) running on a mobile phone (16), establishing a trusted dialogue between the first service processor and the designated website, establishing a trusted dialogue between the first service processor and the second service processor, obtaining activation rights from the designated website by the first service processor, and exercising the activation rights by the first service processor to activate the first edge server and the second edge server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for activating multiple edge servers, and more particularly to a method for activating multiple edge servers within the same local network. Background Technology

[0002] Currently, more and more edge servers are being deployed in the market. However, given that the environment in which edge servers are used is more vulnerable than that of a typical data center, edge servers are generally locked during transportation and therefore require activation to function fully.

[0003] Activating an edge server is inconvenient for many customers. This is because edge sites generally cannot directly connect to related websites (such as Lenovo websites) via mobile networks (such as the internet). Because the ThinkShield Portal is unavailable, the activation function provided on the related website cannot be used. Therefore, some customers need to activate the edge servers using a mobile application, while others need to activate them manually. However, regardless of whether the edge server is activated via a mobile application or manually, each edge server must be activated individually, which is quite time-consuming and labor-intensive.

[0004] Therefore, one object of the present invention is to provide a method for activating at least two edge servers and a multi-server system, in order to mitigate the above-mentioned disadvantages or at least provide a useful alternative for industry and the public. Summary of the Invention

[0005] According to a first aspect of the present invention, a method for activating at least a first edge server and a second edge server is provided, wherein the first edge server includes a first service processor and the second edge server includes a second service processor, the method comprising: data-interoperable connection of the first service processor and the second service processor; data-interoperable connection of the first service processor to a designated website; establishing a trusted session between the first service processor and the designated website; establishing a trusted session between the first service processor and the second service processor; the first service processor obtaining activation rights from the designated website; and the first service processor exercising the activation rights to activate the first edge server and the second edge server.

[0006] According to a second aspect of the present invention, a multi-server system is provided, wherein the system includes at least a first edge server and a second edge server, wherein the first edge server includes a first service processor and the second edge server includes a second service processor, wherein the first service processor and the second service processor are interconnected via data communication, wherein the first service processor is adapted to interconnect with a designated website via data communication, wherein the first service processor is adapted to establish a trusted dialogue with the designated website, wherein the first service processor and the second service processor are adapted to establish a trusted dialogue therebetween, wherein the first service processor is adapted to obtain activation rights from the designated website, and wherein the first service processor is adapted to exercise the activation rights to activate the first edge server and the second edge server. Attached Figure Description

[0007] Embodiments of the invention will now be described by way of example only with reference to the accompanying drawings, wherein:

[0008] Figure 1 A schematic diagram illustrating the arrangement of a method for activating at least two edge servers according to an embodiment of the present invention is shown; and

[0009] Figure 2 Part of the process of activating at least two edge servers according to an embodiment of the present invention is shown. Detailed Implementation

[0010] Figure 1 The diagram illustrates a multi-server system 12 comprised of multiple edge servers 10a, 10b, 10c, and 10d within a local network at an edge site. Each edge server 10a, 10b, 10c, and 10d includes a service processor, such as a Baseboard Management Controller (BMC) 14a, 14b, 14c, and 14d. Assuming that edge servers 10a, 10b, 10c, and 10d are not activated, the BMCs 14a, 14b, 14c, and 14d must first be interconnected for data communication.

[0011] If edge servers 10a, 10b, 10c, and 10d all have wireless network modules, BMCs 14a, 14b, 14c, and 14d can activate these wireless network modules to search for predefined wireless network hotspots, such as Lenovo_Edge_Activation. Simultaneously, one of the edge servers 10a is connected to a mobile phone 16 that is data-interoperable with a mobile network (e.g., the Internet), allowing edge server 10a to data-interoperable with at least one designated website 18 (e.g., ThinkShield Portal) on that mobile network (e.g., the Internet) via mobile phone 16. Furthermore, by executing the mobile phone application 100 on mobile phone 16 (see... Figure 2 Edge server 10a can connect to designated website 18 for data exchange.

[0012] Additionally, if the edge server 10a has a dedicated Long Term Evolution (LTE) hardware module connected to the BMC 14a of the edge server 10a, it can also connect to the mobile cellular network in a data-interoperable manner through this LTE hardware module, so that the edge server 10a can connect to the designated website 18 in a data-interoperable manner.

[0013] After edge server 10a establishes a data communication connection with designated website 18 via mobile phone application 100 running on mobile phone 16, it transforms itself into a wireless network hotspot. It can use a predefined name (e.g., Lenovo_Edge_Activation) and its password can be the public key of designated website 18. Other edge servers 10b, 10c, and 10d in the same edge site's local network simultaneously connect to this wireless network hotspot, enabling their BMCs 14a, 14b, 14c, and 14d to communicate with each other.

[0014] If edge servers 10a, 10b, 10c, and 10d do not have wireless network modules but have internal switch modules, customers / users can connect edge servers 10a, 10b, 10c, and 10d in a daisy chain to communicate with each other, enabling their BMCs 14a, 14b, 14c, and 14d to communicate with each other.

[0015] The internal switch modules of edge servers 10a, 10b, 10c, and 10d are connected to their respective BMCs 14a, 14b, 14c, and 14d. One port of each internal switch module can be connected to the port of the internal switch module of the next edge server, thereby connecting edge servers 10a, 10b, 10c, and 10d to achieve interoperability between BMCs 14a, 14b, 14c, and 14d.

[0016] If edge servers 10a, 10b, 10c, and 10d do not have wireless network modules or internal switch modules, then external switch modules are used to connect edge servers 10a, 10b, 10c, and 10d to enable data communication, allowing their BMCs 14a, 14b, 14c, and 14d to communicate with each other. The external switch module needs to connect to the BMCs 14a, 14b, 14c, and 14d of each edge server 10a, 10b, 10c, and 10d to achieve interoperability between BMCs 14a, 14b, 14c, and 14d.

[0017] After edge servers 10a, 10b, 10c, and 10d are connected so that their BMCs 14a, 14b, 14c, and 14d can communicate with each other, and edge server 10a is connected to the designated website 18 for data exchange, edge server 10a sends an unauthenticated Representational State Transfer Application Programming Interface (RESTAPI) to the other edge servers 10b, 10c, and 10d in the same local network to obtain basic information about edge servers 10b, 10c, and 10d, such as system name, machine type, serial number, or other information.

[0018] Once the BMCs 14a, 14b, 14c, and 14d of each edge server 10a, 10b, 10c, and 10d are interconnected, edge server 10a can automatically discover other edge servers 10b, 10c, and 10d. At this point, the mobile phone 16 connected to edge server 10a will display all edge servers 10a, 10b, 10c, and 10d. If any edge server is not listed on the screen of the mobile phone 16 running the mobile application 100, it indicates a problem with the network connection to that edge server, which needs to be checked and corrected.

[0019] Edge server 10a sends basic information about other edge servers 10b, 10c, and 10d to mobile phone 16. Mobile phone application 100 running on mobile phone 16 lists all edge servers 10a, 10b, 10c, and 10d, allowing customers / users to confirm whether all edge servers 10a, 10b, 10c, and 10d are activated simultaneously.

[0020] Turn to look Figure 2 When a client / user confirms through the mobile application 100 running on the mobile phone 16 that all edge servers 10a, 10b, 10c, 10d or some of them S 102 need to be activated, the mobile application 100 sends one or more of the specified basic information of the edge servers 10a, 10b, 10c, 10d and the identity authentication information of BMC 14a to the designated website 18, requesting the designated website 18 to provide tokens for the edge servers 10a, 10b, 10c, 10d.

[0021] While using mobile phone 16 and mobile application 100 is the most convenient method, other methods are technically possible. For example, a dedicated device can be connected to BMC 14a via the interface on the front panel of edge server 10a, and this device can also connect to a mobile cellular network, thus enabling it to be used for the same activation purpose.

[0022] The request to obtain a token from the designated website 18 is a concatenation of one or more of the specified basic information of the edge servers 10a, 10b, 10c, and 10d and the identity authentication information of BMC 14a (i.e., a signature of the basic information of the edge server 10a signed with the private key of BMC 14a).

[0023] Upon receiving a request for a token, designated website 18 compares and verifies the basic information of edge servers 10a, 10b, 10c, and 10d with the relevant information already stored in the database. If the verification is positive, designated website 18 verifies the identity authentication information of BMC 14a using the private key of BMC 14a stored in the website database. If the verification is positive, designated website 18 generates a token for each edge server 10a, 10b, 10c, and 10d. After completing the above verification process, BMC 14a establishes a trusted dialogue with designated website 18.

[0024] The token includes basic information for each edge server 10a, 10b, 10c, 10d, and the public key of BMC 14a, and is signed with the private key of the designated website 18.

[0025] The token obtained by BMC 14a from the designated website 18 is used to establish a trusted dialogue between BMC 14a and edge servers 10b, 14c, and 10d. This trust is based on BMC 14a being verified by the designated website 18 through the mobile application 100 running on the mobile phone 16, and BMC 14a obtaining a token signed with the private key of the designated website 18 from the designated website 18. Since the public key of the designated website 18 has been stored in the edge servers 10a, 10b, 10c, and 10d after production but before shipment, the edge servers 10b, 10c, and 10d can verify the token to determine whether to trust BMC 14a. Since the token also contains the public key of BMC 14a, edge servers 10b, 10c, and 10d can verify the identity of BMC 14a to allow verification in subsequent steps.

[0026] After BMC 14a provides tokens to BMC 14b, 14c, and 14d of edge servers 10b, 10c, and 10d, and the verification result is positive, and a trusted dialogue is established between BMC 14b, 14c, and 14d of edge servers 10b, 10c, and 10d, mobile phone application 100 requests BMC 14a to provide activation requirement codes S104 for each of edge servers 10a, 10b, 10c, and 10d.

[0027] Based on the token, BMC 14a of edge server 10a requests edge servers 10b, 10c, and 10d to provide their respective activation requirement codes S106, while edge servers 10b, 10c, and 10d, based on trust in the token, provide their respective activation requirement codes S108 to BMC 14a of edge server 10a. BMC 14a of edge server 10a provides the respective activation requirement codes S110 of edge servers 10a, 10b, 10c, and 10d to mobile application 100.

[0028] Mobile application 100 provides the designated website 18 with the activation request codes for each edge server 10a, 10b, 10c, and 10d, and requests the designated website 18 to provide the corresponding activation response S112. The designated website 18 first verifies the activation request codes for each edge server 10a, 10b, 10c, and 10d S114, and after obtaining a positive verification result, generates activation responses for each edge server 10a, 10b, 10c, and 10d S116. The designated website 18 then transmits the activation responses for each edge server 10a, 10b, 10c, and 10d to mobile application 100 S118, and then to edge server 10a S120. The activation response is equivalent to activation rights or activation instructions for each edge server 10a, 10b, 10c, and 10d.

[0029] Upon receiving activation responses from edge servers 10a, 10b, 10c, and 10d, BMC 14a of edge server 10a can first verify the activation response to edge server 10a, then activate edge server 10a (S122), and subsequently transmit the other activation responses to BMCs 14b, 14c, and 14d of edge servers 10b, 10c, and 10d (S124). Upon receiving the corresponding activation responses and verifying their respective activation responses, BMCs 14b, 14c, and 14d of edge servers 10b, 10c, and 10d activate their respective edge servers 10b, 10c, and 10d (S126).

[0030] After activation, edge servers 10b, 10c, and 10d send activation result reports to edge server 10a (S128). Edge server 10a then sends its own activation result, along with reports of activation results from edge servers 10b, 10c, and 10d, to mobile application 100 (S130), which in turn sends them to designated website 18 (S132). Upon receiving the activation results from edge servers 10a, 10b, 10c, and 10d, designated website 18 updates the activation status of each edge server (S134).

[0031] As described above, the multi-server system 12 of the present invention comprises edge servers 10a, 10b, 10c, and 10d, each of which has a BMC 14a, 14b, 14c, or 14d. The BMCs 14a, 14b, 14c, and 14d are interconnected, or at least each BMC 14b, 14c, or 14d is interconnected with BMC 14a. Alternatively, the BMCs 14b, 14c, and 14d can also be interconnected. BMC 14a can be interconnected with a designated website 18 via a mobile application 100 running on a mobile phone 16. According to this arrangement, the multi-server system 12 of the present invention is suitable for performing the method described above for activating the edge servers 10a, 10b, 10c, and 10d.

[0032] It should be understood that the above are merely examples of how the invention can be implemented, and various modifications and / or changes can be made thereto without departing from the spirit of the invention. It should also be understood that, for the sake of brevity, the various features of the invention described in the context of a single embodiment may also be provided individually or in any suitable sub-combination.

Claims

1. A method for activating at least a first edge server and a second edge server, wherein the first edge server includes a first service processor and the second edge server includes a second service processor, the method comprising: The first service processor and the second service processor are connected in a data-interoperable manner. Connect the first service processor to the designated website in a data-interoperable manner. Establish a trusted dialogue between the first service processor and the designated website. Establish a trusted dialogue between the first service processor and the second service processor. The first service processor obtains activation rights from the designated website. The first service processor exercises the activation right to activate the first edge server and the second edge server. Specifically, the first service processor requests the second service processor to provide the activation requirement code for the second edge server. Specifically, the first service processor provides the designated website with the activation requirement code for the first edge server and the activation requirement code for the second edge server. Specifically, after the designated website verifies the activation request code of the first edge server and the activation request code of the second edge server provided by the first service processor, it provides the first service processor with the activation response of the first edge server and the activation response of the second edge server. When the first service processor receives the activation response from the first edge server and the activation response from the second edge server, the first service processor activates the first edge server and transmits the activation response from the second edge server to the second service processor.

2. The method according to claim 1, wherein, The first service processor can connect to the designated website via a mobile phone that can communicate with mobile network data.

3. The method according to claim 1 or 2, wherein, In the step of establishing a trusted dialogue between the first service processor and the designated website, the first service processor provides the designated website with its authentication information and at least one piece of basic information about the second edge server.

4. The method according to claim 3, wherein, The authentication information of the first service processor and the at least one piece of basic information of the second edge server are both encrypted with the private key of the first service processor.

5. The method according to claim 3, in, The designated website verifies the authentication information of the first service processor and the at least one piece of basic information of the second edge server provided by the first service processor, and provides a token to the first service processor if the verification result is positive. In the step of establishing a trusted dialogue between the first service processor and the second service processor, the first service processor provides the token to the second service processor.

6. The method according to claim 1 or 2, wherein, The first edge server and the second edge server include a wireless network module or an internal switch module, and the first service processor and the second service processor can interconnect with each other through the wireless network module or the internal switch module.

7. The method according to claim 1 or 2, wherein, The first edge server and the second edge server can be interconnected with an external switch, and the first service processor and the second service processor can be interconnected with each other through the external switch.

8. A multi-server system: in, The system includes at least a first edge server and a second edge server. The first edge server includes a first service processor, and the second edge server includes a second service processor. The first service processor and the second service processor are interconnected and can communicate with each other. The first service processor is adapted to connect to a designated website in a data-interoperable manner. The first service processor is adapted to establish a trusted dialogue with the designated website, and the first service processor and the second service processor are adapted to establish a trusted dialogue therebetween. The first service processor is adapted to obtain activation rights from the designated website, and the first service processor is adapted to exercise the activation rights to activate the first edge server and the second edge server. The first service processor is adapted to request the second service processor to provide the activation request code for the second edge server. The first service processor is adapted to provide the designated website with the activation request code of the first edge server and the activation request code of the second edge server, and the first service processor is adapted to activate the first edge server and transmit the activation response of the second edge server to the second service processor after receiving the activation response of the first edge server and the activation response of the second edge server from the designated website.

9. The system according to claim 8, wherein, The first service processor is adapted to connect to the designated website via a mobile phone that can communicate with mobile network data.

10. The system according to claim 8 or 9, wherein, The first service processor is adapted to provide the designated website with the authentication information of the first service processor and at least one piece of basic information of the second edge server.

11. The system according to claim 10, wherein, The first service processor is adapted to encrypt the authentication information of the first service processor and the at least one basic information of the second edge server with the private key of the first service processor.

12. The system according to claim 10, wherein, The first service processor is adapted to provide the second service processor with a token obtained from the designated website.

13. The system according to claim 8 or 9, wherein, The first edge server and the second edge server include a wireless network module or an internal switch module to enable them to interconnect and exchange data.

14. The system according to claim 8 or 9, wherein, The first edge server and the second edge server can be interconnected with an external switch to enable data communication between them.

Citation Information

Patent Citations

  • Application security management system and edge server

    CN109525547A

  • Content Delivery Network Server Testing

    US20190363961A1