Cloud Access Control for Data Center Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for updating and configuring computing data centers can be harmful, either intentionally or unintentionally, leading to potential issues with the data center's operation and resource management.

Innovation Solution

Implementing a cloud-based system that determines the access level of operation for users attempting to make changes or updates, enabling or disabling firmware updates and configuration settings based on priority levels, to ensure authorized and safe modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users are permitted to make updates and configuration changes freely, then system adaptability and ease of operation are improved, but system reliability and security deteriorate due to potential harmful modifications

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A cloud-based access level determination system is introduced as an intermediary between users and the firmware/configuration update process. The system receives update requests, determines the user's access level, and only permits changes if the access level is sufficient. This mediator resolves the contradiction by enabling flexible updates for authorized users while blocking potentially harmful changes from unauthorized users, thus maintaining both adaptability and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control restrictions are implemented to prevent harmful modifications, then system reliability is improved, but ease of operation deteriorates due to limited user autonomy

Engineering Contradiction:
Improvesystem stabilityVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access control system operates autonomously by automatically determining user access levels and making authorization decisions without requiring manual intervention from administrators. The cloud-based system self-evaluates each update request against stored access level criteria and automatically permits or denies the operation. This self-service approach maintains reliability through consistent access control while preserving user ease of operation for authorized users who experience no additional friction in the update process.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If cloud-based access level determination is implemented, then harmful factors are reduced, but device complexity increases due to additional control mechanisms

Engineering Contradiction:
Improveharmful modificationsVSAvoidcontrol system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex access level determination logic and access level database are extracted from the local devices and relocated to a centralized cloud-based system. Individual devices only retain minimal client functionality to communicate update requests and receive authorization decisions. This extraction eliminates the need for each device to maintain complex access control mechanisms locally, thereby reducing device complexity while still providing comprehensive protection against harmful modifications through centralized cloud-based validation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240372792A1Techniques to control system updates and configuration changes via the cloud
Publication Date: 2024.11.07 INTEL CORP
  • US20240372792A1 patent drawing
  • US20240372792A1 patent drawing
  • US20240372792A1 patent drawing

AI summary

Embodiments are generally directed apparatuses, methods, techniques and so forth determine an access level of operation based on an indication received via one or more network links from a pod management controller, and enable or disable a firmware update capability for a firmware device based on the access level of operation, the firmware update capability to change firmware for the firmware device. Embodiments may also include determining one or more configuration settings of a plurality of configuration settings to enable for configuration based on the access level of operation, and enable configuration of the one or more configuration settings.