Bare Metal Device Management via Pre-OS Boot Agent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device management systems face challenges in provisioning and configuring computing devices before they boot up, particularly in non-APPLE ecosystems, where there is no central repository for tracking ownership and configurations, leading to difficulties in ensuring secure and compliant OS configurations, and lacking efficient recovery options.
Innovation Solution
Implementing a bare metal device management system that configures firmware to contact a network address before booting, using a boot agent to manage the boot process, ensure compliance, and provide pre-OS recovery options, allowing for remote provisioning and compliance checking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional device enrollment is used, then users can access the device, but device management cannot begin until after boot and user enrollment is required
Solution Approach 1:
The patent implements preliminary provisioning by configuring firmware to contact a network address before the OS boots. The boot agent is downloaded and installed during pre-OS operations, enabling device management enrollment to occur before the user accesses the device, thereby eliminating the time loss associated with post-boot enrollment
2Loss of time
If preliminary provisioning is implemented, then device management can start before boot, but it requires administrator enrollment prior to user access
Solution Approach 1:
The patent implements self-service by making the firmware automatically contact the network address and the boot agent automatically download and install itself during the pre-OS boot process. This eliminates the need for administrator intervention to enroll each device manually, reducing provisioning complexity while enabling pre-boot device management
3Ease of operation
If users are allowed to boot into OS, then user access is enabled, but noncompliant configurations can be loaded that bypass management agents
Solution Approach 1:
The patent implements preliminary configuration by having the boot agent download and apply the OS configuration image during pre-OS operations, before the user can access the device. The boot order is then modified to ensure this configured OS boots first, preventing users from loading noncompliant configurations that would bypass management agents
4Adaptability or versatility
If multiple boot paths are available, then boot flexibility is provided, but control over managed boot process is reduced
Solution Approach 1:
The patent implements dynamic boot order management by having the boot agent modify the boot order at runtime. The configured OS is placed first in the boot order to ensure it boots and maintains compliance, while other boot paths remain available but are executed only if the primary configured OS fails to boot, thus providing both control and flexibility
Data Source
AI summary
Examples described herein include systems and methods for bare metal management of computing devices. Firmware of the computing device can be configured to contact a network location as part of an HTTP boot and download a boot agent. The boot agent can be prioritized to execute before a primary OS boot loader. The boot agent can download an OS configuration including a package that is inserted into the primary OS. The primary OS, as configured, can then boot. The boot agent can also attest to OS health and device compliance on subsequent boots. For example, the boot agent can cause the firmware to track how many boots have occurred since compliance verification. If a threshold number of boots occur without verification, the boot agent can initiate restoration. Alternatively, if a decommission flag is set, the boot agent can cause the computing device to boot into its original configuration.


