Automated Provisioning of Active Management Technology Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional active management technology requires manual input of sensitive information by IT technicians for setup and configuration, which is time-consuming and insecure, especially due to reliance on weaker authentication methods like HTTP digest authentication.

Innovation Solution

A live operating system compact disk is created with a setup and configuration client that automates the provisioning process using secure protocols like TLS and Kerberos authentication, along with a script to retrieve and set predefined parameters, enabling secure and efficient configuration of active management technology devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual input of sensitive information is used for setup and configuration, then security is compromised due to weaker authentication methods, but automation is reduced requiring IT technician intervention

Engineering Contradiction:
ImprovesecurityVSAvoidautomation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent applies preliminary action by pre-configuring secure authentication credentials (Kerberos tickets, TLS certificates) on the installation media before deployment. The setup and configuration client is pre-loaded with the capability to perform secure authentication, eliminating the need for manual credential input during installation and ensuring secure protocols are used by default.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through the setup and configuration client that automatically performs secure authentication and configuration tasks without requiring IT technician intervention. The client autonomously retrieves parameters, establishes secure connections using Kerberos and TLS, and configures the active management technology device, thereby improving both security and automation.

Inventive Principle:
Principle #25Self-service

2Loss of time

If manual configuration is performed by IT technicians, then setup time is increased, but security protocols may be weakened due to reliance on simpler authentication methods

Engineering Contradiction:
Improvesetup timeVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent replaces the mechanical process of manual credential input and configuration with an automated software-based system. The setup and configuration client automatically performs authentication using Kerberos and TLS protocols, substituting the manual mechanical process with an automated electronic process that is both faster and more secure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the authentication parameter from weak HTTP digest authentication to strong Kerberos and TLS authentication. This parameter change is enforced by the automated configuration process, which retrieves and applies secure authentication parameters, thereby improving security while reducing setup time through automation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secure protocols like TLS and Kerberos authentication are implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of secure protocol implementation into a separate setup and configuration client component. This client handles all the complex Kerberos authentication and TLS certificate management, isolating the complexity from the core active management technology device. The device itself remains simple, while the client manages the security complexity externally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The setup and configuration client acts as an intermediary between the installer and the active management technology device. It handles the complex secure authentication protocols and communicates with the device, shielding the device from direct exposure to complex security mechanisms while ensuring secure configuration through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If automated provisioning is implemented using live operating system compact disk, then ease of operation is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveease of operationVSAvoidmanufacturing
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent merges the operating system, setup and configuration client, and provisioning scripts into a single live operating system compact disk image. This consolidation simplifies the manufacturing process by creating a single deployable unit that contains all necessary components, while providing ease of operation through automated provisioning when the disk is booted and executed.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8291203B2Using a live operating system to set up and configure an active management technology device
Publication Date: 2012.10.16 TAHOE RES LTD
  • US8291203B2 patent drawing
  • US8291203B2 patent drawing
  • US8291203B2 patent drawing

AI summary

An active management technology device may be provisioned using a live operating system stored on a disk, in one embodiment. After disk insertion, no further operator involvement may be needed in some cases.