Data Center Asset Authentication via Cloud Connector Inversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based data center management systems face challenges with one-way communication channels hindered by firewalls, proxies, and complex network setups, necessitating an always-connected, bidirectional connection for secure real-time management of data center assets.

Innovation Solution

A connectivity management system that establishes a secure communication channel between a data center asset client module and a connectivity management system, authenticates the client module, and configures software in response to authentication, enabling secure, real-time management of data center assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-way communication channel is used through firewalls and proxies, then network security is maintained, but real-time bidirectional connectivity for asset management is hindered

Engineering Contradiction:
Improvenetwork securityVSAvoidreal-time bidirectional connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of having the management system initiate connections through firewalls (one-way), the patent inverts the approach by having the data center asset establish an outbound connection to a cloud connector, which then creates a reverse channel back to the asset. This allows bidirectional communication while maintaining firewall rules.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a cloud connector as an intermediary component that sits between the data center asset and the management system. This mediator establishes secure communication channels, allowing real-time bidirectional connectivity without requiring direct penetration through firewall and proxy barriers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If complex network setups with firewalls and proxies are used, then network security and isolation are maintained, but communication channels for asset management become hindered

Engineering Contradiction:
Improvenetwork security protectionVSAvoidcommunication channel availability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent performs preliminary actions by pre-deploying cloud connectors within the data center network perimeter before management operations are needed. These connectors are pre-configured to establish communication channels, ensuring that when asset management is required, the communication pathways are already in place and functional.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cloud connector acts as an intermediary that bridges the isolated data center network and the external management system. It maintains network security by staying within the perimeter while providing the necessary communication channels for asset management, thus preventing information loss without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication and software configuration steps are added, then security and proper asset management are improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication and configuration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the data center asset automatically performs authentication and software configuration through the cloud connector. The asset can autonomously establish secure channels, authenticate itself, and configure management software without requiring manual intervention, thus improving security while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12003382B2Data center asset client module authentication via a connectivity management authentication operation
Publication Date: 2024.06.04 DELL PROD LP
  • US12003382B2 patent drawing
  • US12003382B2 patent drawing
  • US12003382B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a data center connectivity management operation. The connectivity management operation includes: providing a data center asset with a data center asset client module and an embedded data center asset client module; establishing a secure communication channel between the connectivity management system client and a connectivity management system; exchanging information between the connectivity management system client and the connectivity management system via the secure communication channel between the connectivity management system client and the connectivity management system, the information including a data center asset client module authentication request; authenticating the data center asset client module in response to the data center asset module authentication request; and, configuring software in the data center asset in response to authentication of the data center asset client module.