Access Controller Secure Provisioning Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional bare-metal provisioning of information handling systems lacks secure authentication mechanisms, allowing rogue systems to potentially jeopardize enterprise data by being maliciously introduced into networks without proper verification.

Innovation Solution

Implementing an access controller with stored enterprise and platform private keys, along with their respective public keys, to establish an asymmetrically cryptographic communications channel with a provisioning server, ensuring mutual authentication and secure provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional bare-metal provisioning is used without authentication mechanisms, then provisioning speed and automation are improved, but system security and reliability deteriorate allowing rogue systems to be maliciously introduced

Engineering Contradiction:
Improveprovisioning speedVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions before provisioning occurs. The access controller and provisioning server perform mutual authentication using cryptographic key pairs prior to any provisioning operations. This preliminary security verification ensures that only authorized systems can be provisioned, preventing rogue systems from being maliciously introduced while maintaining automated provisioning capabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic authentication mechanisms as intermediaries between the access controller and provisioning server. Digital certificates and key pairs act as mediators that verify identities without requiring manual intervention, enabling automated secure provisioning. The intermediary authentication layer ensures reliability while maintaining productivity through automation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mutual authentication with cryptographic keys is implemented, then system security and reliability are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcryptographic implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the access controller and provisioning server automatically perform mutual authentication using pre-configured cryptographic key pairs. The system autonomously verifies identities and establishes secure communication channels without requiring manual cryptographic operations or complex configuration by administrators, thereby reducing implementation complexity while maintaining high security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Cryptographic key pairs and digital certificates are pre-configured on the access controller and provisioning server before deployment. This preliminary setup eliminates the need for complex real-time key generation and management during provisioning operations, reducing device complexity while ensuring reliable authentication security

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automated bare-metal provisioning is used without verification, then administrator interaction is reduced, but the risk of malicious provisioning increases

Engineering Contradiction:
Improveautomation levelVSAvoidmalicious provisioning risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the access controller receives authentication responses from the provisioning server and verifies digital certificates before proceeding with provisioning. This feedback loop ensures that automated provisioning only occurs after successful mutual authentication, preventing malicious provisioning while maintaining ease of operation through automation. The system automatically stops the provisioning process if authentication fails

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Digital certificates and cryptographic authentication protocols serve as intermediaries in the automated provisioning process. These intermediaries verify the legitimacy of both the access controller and provisioning server before any provisioning actions occur, eliminating the need for administrator interaction while preventing malicious provisioning through automated security verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9660816B2System and method for secure provisioning of an information handling system
Publication Date: 2017.05.23 DELL PROD LP
  • US9660816B2 patent drawing
  • US9660816B2 patent drawing
  • US9660816B2 patent drawing

AI summary

Systems and methods for reducing problems and disadvantages associated with provisioning of information handling systems, including without limitation those associated with bare metal provisioning of information handling systems, are disclosed. A system may include a processor, and a memory and an access controller each communicatively coupled to the processor. The access controller may store an enterprise public key associated with an enterprise private key and a platform private key associated with the system. The access controller may be configured to: (i) authenticate communications received from a provisioning server communicatively coupled to the access controller based at least on an enterprise public certificate associated with the provisioning server and (ii) establish an asymmetrically cryptographic communications channel between the access controller and the provisioning server based at least on a platform public key associated with the platform private key, the platform private key, the enterprise public key, and the enterprise private key.