Access Controller Assisted Network Boot Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securely configuring information handling systems to perform network boots is challenging due to limited processing capabilities before booting, and ensuring network boots are secure is difficult.

Innovation Solution

An information handling system comprising a processor, memory, and an access controller that receives boot configuration information from a management server, generates a boot script, and creates a specific pre-boot file to configure the system to boot securely from a remote target, using protocols like iSCSI or HTTPS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network booting is implemented to allow centralized management and cluster computing, then storage management efficiency is improved, but security configuration difficulty increases due to limited processing capabilities before booting

Engineering Contradiction:
Improvestorage management efficiencyVSAvoidsecurity configuration difficulty
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The access controller performs preliminary actions by storing authentication credentials and boot configuration information before the information handling system boots. The controller prepares security policies and boot parameters in advance, then presents them to the system during the boot process, eliminating the need for complex post-boot security configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access controller serves as an intermediary between the information handling system and the network boot infrastructure. It handles security authentication, credential verification, and boot parameter management, shielding the limited-processing system from complex security configuration tasks while enabling centralized storage management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional network booting is used to enable remote booting, then boot flexibility is improved, but security risks increase due to difficulty in ensuring secure network boots

Engineering Contradiction:
Improveboot flexibilityVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Authentication credentials and security policies are pre-configured in the access controller before the network boot process begins. The controller validates boot parameters and authentication information in advance, ensuring security is established before the system connects to remote boot resources, thus maintaining both flexibility and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access controller implements feedback mechanisms by continuously monitoring boot parameters, authentication responses, and system state during the network boot process. It adjusts security policies and boot configuration dynamically based on validated information, ensuring secure remote booting while maintaining adaptability to different boot scenarios.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9489212B2System and method for an access controller assisted boot
Publication Date: 2016.11.08 DELL PROD LP
  • US9489212B2 patent drawing
  • US9489212B2 patent drawing
  • US9489212B2 patent drawing

AI summary

Systems and methods for reducing problems and disadvantages associated with network boots are disclosed. In accordance with an embodiment of the present disclosure, an information handling system comprises a processor, a memory communicatively coupled to the processor, and an access controller communicatively coupled to the processor. The access controller has stored thereon a general pre-boot file and configured to receive boot configuration information from a management server. The access controller further configured to generate a boot script according to the boot configuration information and generate a specific pre-boot file based on the general pre-boot file and the boot script. The access controller is further configured to configure the information handling system to boot to a target based on the specific pre-boot file.