Channel Card Software Entitlement via Out-of-Band Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems face challenges in managing entitlement to use proprietary software for non-standard hardware components, such as aftermarket channel cards, which require specialized software that may compromise the system if not properly authenticated.

Innovation Solution

A management controller in the data processing system obtains a signed data structure from the non-standard channel card using a private key, verifies it via out-of-band communication with a remote system, and facilitates the use of proprietary software without traversing the system's hardware resources, ensuring secure access to non-standard functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary software is used for nonstandard channel cards, then functionality and adaptability are improved, but system security and reliability deteriorate due to potential compromise from unauthenticated software

Engineering Contradiction:
ImprovefunctionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary authentication by obtaining a signed data structure from the nonstandard channel card before allowing proprietary software execution. The management controller verifies the signature using a public key associated with the channel card, ensuring the software is authenticated and authorized prior to loading, thus preventing unauthenticated software from compromising system security while enabling legitimate functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a management controller as an intermediary between the nonstandard channel card and the proprietary software. The management controller mediates the authentication process by obtaining the signed data structure, verifying the signature, and controlling the loading of proprietary software based on verification results, thereby isolating the system from direct exposure to potentially malicious software while enabling authorized functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If proprietary software is loaded onto hardware resources, then access to nonstandard functions is enabled, but the system becomes vulnerable to compromise from malicious or unauthenticated software

Engineering Contradiction:
Improveaccess to nonstandard functionsVSAvoidsystem vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication by verifying a signature on a data structure obtained from the nonstandard channel card before loading proprietary software onto hardware resources. The management controller uses a public key associated with the channel card to verify the signature, ensuring only authenticated software is loaded, thus preventing malicious software from compromising system security while enabling legitimate nonstandard functions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management controller serves as an intermediary that controls the loading of proprietary software onto hardware resources. It obtains a signed data structure from the channel card, verifies the signature, and only permits software loading after successful verification, thereby protecting hardware resources from unauthenticated or malicious software while enabling authorized nonstandard functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If standard hardware components are used, then system security is maintained, but adaptability and ability to use specialized software are limited

Engineering Contradiction:
Improvesystem securityVSAvoidsoftware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent maintains system security by performing preliminary authentication of nonstandard channel cards before allowing proprietary software execution. The management controller verifies a signature using a public key associated with the channel card, ensuring only authenticated devices can load specialized software, thus extending adaptability while maintaining the security standards of traditional systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management controller acts as an intermediary that enables nonstandard channel cards to interact securely with the system. It verifies authentication credentials and controls software loading, allowing specialized hardware with enhanced functionality to be integrated while maintaining system security through centralized authentication and authorization management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260030327A1Managing entitlement to use software by components of a data processing system
Publication Date: 2026.01.29 DELL PROD LP
  • US20260030327A1 patent drawing
  • US20260030327A1 patent drawing
  • US20260030327A1 patent drawing

AI summary

Methods and systems for managing operations of a data processing system are disclosed. To manage operations of the data processing system, an identification may be made that a channel card of the data processing system is a non-standard channel card configured to perform at least one non-standard function. Based on the identification, a management controller of the data processing system may obtain a signed data structure indicating an entitlement for the channel card, the signed data structure including a signature usable to verify the channel card is entitled to use of proprietary software. The management controller may perform a verification process to determine whether the signed data structure is usable to establish the entitlement via at least an out-of-band interaction with a remote system. If the signed data structure is usable to establish the entitlement, computer-implemented services may be provided using the channel card and the proprietary software.