Centralized Management Controller Delegated Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Delegated authorization systems in information handling systems require cumbersome configuration processes, especially when multiple management controllers need to be individually set up for external network connections to validate access tokens, which is inconvenient and inefficient.

Innovation Solution

Implementing a management controller that communicatively couples with target management controllers to receive and validate tokens, allowing the management controller to service requests based on validation, thereby centralizing the delegated authorization process and eliminating the need for individual configuration of each management controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each management controller is individually configured for external network connections to validate access tokens, then token validation can be performed, but the configuration burden and system complexity increase significantly

Engineering Contradiction:
Improvetoken validation capabilityVSAvoidconfiguration burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the token validation function from individual management controllers into a centralized authorization server. Instead of each management controller independently validating tokens via external network connections, all validation requests are routed through the single centralized server, consolidating the functionality and reducing configuration complexity across multiple devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized authorization server acts as an intermediary between management controllers and the token validation process. Management controllers send validation requests to this intermediary server, which then handles the external network communication and token verification, eliminating the need for each controller to have direct external network access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each management controller connects to external network for token validation, then access control can be enforced, but the time and resources required for configuration and maintenance increase

Engineering Contradiction:
Improveaccess control enforcementVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary configuration by establishing a single centralized authorization server that pre-configures token validation capabilities. This preliminary setup eliminates the need for repeated configuration actions on each management controller, as the centralized server handles all validation requests with pre-established credentials and validation rules

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple management controllers are individually configured with external network access, then each can independently validate tokens, but the ease of operation decreases due to repetitive configuration steps

Engineering Contradiction:
Improveindependent token validationVSAvoidconfiguration convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The centralized authorization server provides universal token validation functionality that serves all management controllers through a single interface. This multi-functional server handles validation requests from any number of controllers using the same configuration, eliminating the need for repetitive setup steps while maintaining consistent validation capabilities across the entire system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11669645B2Delegated authorization via chassis management controller
Publication Date: 2023.06.06 DELL PROD LP
  • US11669645B2 patent drawing
  • US11669645B2 patent drawing
  • US11669645B2 patent drawing

AI summary

An information handling system may include a management controller; and a plurality of target information handling systems each including a target management controller that is communicatively coupled to the management controller. The information handling system may be configured to: receive, at a particular target management controller and from a client information handling system, a request for management associated with the particular target management controller; perform, at the management controller, validation of a token associated with the request; and based on the validation, cause the particular target management controller to service the request.