Data Center Asset Authentication via Cloud Connector Inversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based data center management systems face challenges with one-way communication channels hindered by firewalls, proxies, and complex network setups, necessitating an always-connected, bidirectional connection for secure real-time management of data center assets.
Innovation Solution
A connectivity management system that establishes a secure communication channel between a data center asset client module and a connectivity management system, authenticates the client module, and configures software in response to authentication, enabling secure, real-time management of data center assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a one-way communication channel is used through firewalls and proxies, then network security is maintained, but real-time bidirectional connectivity for asset management is hindered
Solution Approach 1:
Instead of having the management system initiate connections through firewalls (one-way), the patent inverts the approach by having the data center asset establish an outbound connection to a cloud connector, which then creates a reverse channel back to the asset. This allows bidirectional communication while maintaining firewall rules.
Solution Approach 2:
The patent introduces a cloud connector as an intermediary component that sits between the data center asset and the management system. This mediator establishes secure communication channels, allowing real-time bidirectional connectivity without requiring direct penetration through firewall and proxy barriers.
2Object-affected harmful factors
If complex network setups with firewalls and proxies are used, then network security and isolation are maintained, but communication channels for asset management become hindered
Solution Approach 1:
The patent performs preliminary actions by pre-deploying cloud connectors within the data center network perimeter before management operations are needed. These connectors are pre-configured to establish communication channels, ensuring that when asset management is required, the communication pathways are already in place and functional.
Solution Approach 2:
The cloud connector acts as an intermediary that bridges the isolated data center network and the external management system. It maintains network security by staying within the perimeter while providing the necessary communication channels for asset management, thus preventing information loss without compromising security.
3Reliability
If authentication and software configuration steps are added, then security and proper asset management are improved, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the data center asset automatically performs authentication and software configuration through the cloud connector. The asset can autonomously establish secure channels, authenticate itself, and configure management software without requiring manual intervention, thus improving security while reducing operational complexity.
Data Source
AI summary
A system, method, and computer-readable medium are disclosed for performing a data center connectivity management operation. The connectivity management operation includes: providing a data center asset with a data center asset client module and an embedded data center asset client module; establishing a secure communication channel between the connectivity management system client and a connectivity management system; exchanging information between the connectivity management system client and the connectivity management system via the secure communication channel between the connectivity management system client and the connectivity management system, the information including a data center asset client module authentication request; authenticating the data center asset client module in response to the data center asset module authentication request; and, configuring software in the data center asset in response to authentication of the data center asset client module.


