Automated Credential Reservation for Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data center monitoring systems face challenges in securely and efficiently exchanging sensitive data across networks, as pre-programmed authentication credentials are prone to security vulnerabilities and labor-intensive to manage.

Innovation Solution

An automated credential reservation system is implemented, where computers verify and derive unique credentials for secure bidirectional communication, reducing the need for manual credential management and enhancing security through periodic credential changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-programmed authentication credentials are used for secure communication, then security is improved, but manual credential management becomes labor-intensive and vulnerable to security breaches

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables computers to automatically generate, exchange, and manage their own authentication credentials without human intervention. Each computer autonomously creates credentials, transmits them to authorized counterparts, and handles verification processes, eliminating the need for manual credential distribution and management while maintaining security through automated cryptographic operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes credential parameters over time through periodic regeneration and automatic rotation. Credentials are not static but evolve with changing system conditions, time intervals, and security requirements, making the system adaptable to emerging threats while reducing the burden of manual credential updates

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual credential management is used, then security control is maintained, but time and labor resources are consumed

Engineering Contradiction:
Improvesecurity controlVSAvoidcredential management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs credential generation, verification, and exchange operations in advance before they are needed for actual communication. Credentials are pre-established between computer pairs, and verification mechanisms are set up beforehand, eliminating the need for time-consuming manual credential management during critical communication events

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Computers autonomously handle the entire credential lifecycle including generation, storage, transmission, and verification without requiring human time investment. The automated system manages credential security controls, periodic updates, and regeneration tasks, freeing administrators from time-consuming manual interventions while maintaining rigorous security standards

Inventive Principle:
Principle #25Self-service

3Device complexity

If static credentials are used, then system complexity is reduced, but security vulnerabilities increase due to periodic credential changes needed

Engineering Contradiction:
Improvecredential system complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transitions from static credentials to dynamic, adaptive credentials that automatically adjust to changing conditions. Credentials are regenerated based on time intervals, security events, or system conditions, creating a living authentication system that responds to threats without requiring complex manual reconfiguration or increasing operational complexity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10642849B2Methods and systems for providing improved access to data and measurements in a management system
Publication Date: 2020.05.05 SCHNEIDER ELECTRIC IT CORP
  • US10642849B2 patent drawing
  • US10642849B2 patent drawing
  • US10642849B2 patent drawing

AI summary

A method of managing device data related to a data center infrastructure includes generating, by a first server, a first portion of the device data in response to a change in a status of at least one of a plurality of data center infrastructure devices, storing, by a second server, the first portion of the device data in a database, generating, by the first server, a second portion of the device data in response to a request for data that is not contained in the database, the second portion of the device data being different than the first portion of the device data and being generated in a lightweight format, and displaying, in response to a user request, at least a portion of the device data using a user interface that is provided to the client computer by the second server.