Client Device Link-Layer Credential Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring large-scale computer systems like high-performance clusters and datacenters is time-consuming and insecure due to the need for manual handling of credentials, which can lead to man-in-the-middle attacks and long-term security issues.

Innovation Solution

A method where client devices form link-layer protocol packets with unique credentials and send them to a network device, allowing a management system to obtain and use these credentials to change the client devices from a first configuration to a second, thereby securing the system and enabling automated configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unknown credentials are implemented in each compute node to maintain security during bring-up phase, then security is improved, but automation and ease of configuring the computer system is inhibited

Engineering Contradiction:
ImprovesecurityVSAvoidease of configuring
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically generating unique credentials for each compute node before the configuration process begins. These credentials are pre-configured and stored in a credential store, allowing the management system to automatically authenticate and configure nodes without manual intervention, thus maintaining security while enabling automation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each compute node automatically generates its own unique credentials and makes them available through the link-layer protocol. The nodes self-configure by receiving configuration data through automated authentication, eliminating the need for manual credential distribution and configuration, thereby maintaining security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual credential handling is used for configuration, then security control is maintained, but configuration time increases considerably

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system replaces manual mechanical credential handling with automated electronic credential distribution. The management system automatically retrieves credentials from the credential store, transmits them through the link-layer protocol to compute nodes, and performs configuration without human intervention, thus maintaining security control while dramatically reducing configuration time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated credential distribution and configuration process operates continuously without interruption. The management system systematically iterates through all compute nodes, automatically authenticating and configuring each one in sequence, eliminating the downtime and delays associated with manual credential handling and configuration.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If current configuration methods are used, then configuration process is simple, but man-in-the-middle attacks cannot be prevented resulting in long-term security issues

Engineering Contradiction:
Improveconfiguration process simplicityVSAvoidman-in-the-middle attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The management system acts as a secure intermediary between credential distribution and compute node authentication. It establishes secure communication channels through the link-layer protocol, verifying credentials before allowing configuration, thus preventing man-in-the-middle attacks while maintaining configuration process simplicity through automated mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10298574B2Managing client device credentials to facilitate secure computer system configuration
Publication Date: 2019.05.21 LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD
  • US10298574B2 patent drawing
  • US10298574B2 patent drawing
  • US10298574B2 patent drawing

AI summary

A method includes a client device forming a link-layer protocol packet having a field that includes first credentials of the client device and sending the link-layer protocol packet to a directly attached network device while the client device is in a first configuration. The method further includes a management system obtaining the first credentials from the network device and using the first credentials to access the client device and change the client device from the first configuration to a second configuration. Optionally, a computer system may include a plurality of client devices that implement the method to facilitate securely configuring the entire computer system. Preferably, each client device generates system-unique first credentials.