Automated Provisioning of Active Management Technology Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional active management technology requires manual input of sensitive information by IT technicians for setup and configuration, which is time-consuming and insecure, especially due to reliance on weaker authentication methods like HTTP digest authentication.
Innovation Solution
A live operating system compact disk is created with a setup and configuration client that automates the provisioning process using secure protocols like TLS and Kerberos authentication, along with a script to retrieve and set predefined parameters, enabling secure and efficient configuration of active management technology devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual input of sensitive information is used for setup and configuration, then security is compromised due to weaker authentication methods, but automation is reduced requiring IT technician intervention
Solution Approach 1:
The patent applies preliminary action by pre-configuring secure authentication credentials (Kerberos tickets, TLS certificates) on the installation media before deployment. The setup and configuration client is pre-loaded with the capability to perform secure authentication, eliminating the need for manual credential input during installation and ensuring secure protocols are used by default.
Solution Approach 2:
The system implements self-service through the setup and configuration client that automatically performs secure authentication and configuration tasks without requiring IT technician intervention. The client autonomously retrieves parameters, establishes secure connections using Kerberos and TLS, and configures the active management technology device, thereby improving both security and automation.
2Loss of time
If manual configuration is performed by IT technicians, then setup time is increased, but security protocols may be weakened due to reliance on simpler authentication methods
Solution Approach 1:
The patent replaces the mechanical process of manual credential input and configuration with an automated software-based system. The setup and configuration client automatically performs authentication using Kerberos and TLS protocols, substituting the manual mechanical process with an automated electronic process that is both faster and more secure.
Solution Approach 2:
The system changes the authentication parameter from weak HTTP digest authentication to strong Kerberos and TLS authentication. This parameter change is enforced by the automated configuration process, which retrieves and applies secure authentication parameters, thereby improving security while reducing setup time through automation.
3Reliability
If secure protocols like TLS and Kerberos authentication are implemented, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent extracts the complexity of secure protocol implementation into a separate setup and configuration client component. This client handles all the complex Kerberos authentication and TLS certificate management, isolating the complexity from the core active management technology device. The device itself remains simple, while the client manages the security complexity externally.
Solution Approach 2:
The setup and configuration client acts as an intermediary between the installer and the active management technology device. It handles the complex secure authentication protocols and communicates with the device, shielding the device from direct exposure to complex security mechanisms while ensuring secure configuration through the intermediary layer.
4Ease of operation
If automated provisioning is implemented using live operating system compact disk, then ease of operation is improved, but manufacturing complexity increases
Solution Approach 1:
The patent merges the operating system, setup and configuration client, and provisioning scripts into a single live operating system compact disk image. This consolidation simplifies the manufacturing process by creating a single deployable unit that contains all necessary components, while providing ease of operation through automated provisioning when the disk is booted and executed.
Data Source
AI summary
An active management technology device may be provisioned using a live operating system stored on a disk, in one embodiment. After disk insertion, no further operator involvement may be needed in some cases.


