Bare Metal Device Management via Pre-OS Boot Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device management systems face challenges in provisioning and configuring computing devices before they boot up, particularly in non-APPLE ecosystems, where there is no central repository for tracking ownership and configurations, leading to difficulties in ensuring secure and compliant OS configurations, and lacking efficient recovery options.

Innovation Solution

Implementing a bare metal device management system that configures firmware to contact a network address before booting, using a boot agent to manage the boot process, ensure compliance, and provide pre-OS recovery options, allowing for remote provisioning and compliance checking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional device enrollment is used, then users can access the device, but device management cannot begin until after boot and user enrollment is required

Engineering Contradiction:
ImproveDevice accessibilityVSAvoidTime to enroll device
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary provisioning by configuring firmware to contact a network address before the OS boots. The boot agent is downloaded and installed during pre-OS operations, enabling device management enrollment to occur before the user accesses the device, thereby eliminating the time loss associated with post-boot enrollment

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If preliminary provisioning is implemented, then device management can start before boot, but it requires administrator enrollment prior to user access

Engineering Contradiction:
ImproveTime to enroll deviceVSAvoidProvisioning process complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements self-service by making the firmware automatically contact the network address and the boot agent automatically download and install itself during the pre-OS boot process. This eliminates the need for administrator intervention to enroll each device manually, reducing provisioning complexity while enabling pre-boot device management

Inventive Principle:
Principle #25Self-service

3Ease of operation

If users are allowed to boot into OS, then user access is enabled, but noncompliant configurations can be loaded that bypass management agents

Engineering Contradiction:
ImproveUser access to deviceVSAvoidOS configuration compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary configuration by having the boot agent download and apply the OS configuration image during pre-OS operations, before the user can access the device. The boot order is then modified to ensure this configured OS boots first, preventing users from loading noncompliant configurations that would bypass management agents

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple boot paths are available, then boot flexibility is provided, but control over managed boot process is reduced

Engineering Contradiction:
ImproveBoot path optionsVSAvoidBoot process control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic boot order management by having the boot agent modify the boot order at runtime. The configured OS is placed first in the boot order to ensure it boots and maintains compliance, while other boot paths remain available but are executed only if the primary configured OS fails to boot, thus providing both control and flexibility

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11669337B2Bare metal device management
Publication Date: 2023.06.06 OMNISSA LLC
  • US11669337B2 patent drawing
  • US11669337B2 patent drawing
  • US11669337B2 patent drawing

AI summary

Examples described herein include systems and methods for bare metal management of computing devices. Firmware of the computing device can be configured to contact a network location as part of an HTTP boot and download a boot agent. The boot agent can be prioritized to execute before a primary OS boot loader. The boot agent can download an OS configuration including a package that is inserted into the primary OS. The primary OS, as configured, can then boot. The boot agent can also attest to OS health and device compliance on subsequent boots. For example, the boot agent can cause the firmware to track how many boots have occurred since compliance verification. If a threshold number of boots occur without verification, the boot agent can initiate restoration. Alternatively, if a decommission flag is set, the boot agent can cause the computing device to boot into its original configuration.