Management Controller Key Storage for Seamless Secure Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face security and efficiency issues during component replacement in computing devices, as the authentication keys for newly replaced components are not readily available, necessitating a complete re-spin of the host's build, which is costly and burdensome.

Innovation Solution

Implementing a management controller with a device key repository that stores authentication keys independently from the host processing unit, allowing seamless access to newly replaced components without requiring a complete re-spin of the host's build.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication keys are stored in the host processor, then the boot-up process can be completed, but security vulnerabilities arise when components are replaced

Engineering Contradiction:
ImprovesecurityVSAvoidboot-up completeness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication key storage function from the host processor and places it in a separate management controller. This extraction resolves the security vulnerability by isolating key storage from the potentially compromised host environment, while the management controller ensures boot-up completeness by providing keys to authorized components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The management controller acts as an intermediary between the host processor and secured components. It mediates authentication by storing keys securely and providing them to components that need them, resolving both the security concern (by controlling key access) and the boot-up completeness requirement (by enabling authorized components to authenticate).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication keys are updated after component replacement, then security is maintained, but the boot-up process becomes incomplete

Engineering Contradiction:
ImprovesecurityVSAvoidboot-up efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The management controller performs preliminary actions by pre-storing authentication keys for multiple components before they are replaced. When a component is replaced, the controller can immediately provide the appropriate key without interrupting the boot-up process, thus maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adapts to component replacement by allowing the management controller to switch between different authentication keys based on which component is present. This dynamic key management ensures security is maintained while avoiding boot-up failures, resolving the contradiction between security and efficiency.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the host's build is re-spun after component replacement, then authentication is restored, but costs and time increase

Engineering Contradiction:
ImproveauthenticationVSAvoidre-spin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By extracting authentication key management from the host build process to a separate management controller, the system eliminates the need to re-spin the entire host build when components are replaced. The management controller independently handles key updates, restoring authentication without time-consuming re-spins.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter of key storage location from 'inside host build' to 'in management controller'. This parameter change allows authentication to be restored by simply updating which key the management controller provides, rather than re-spinning the entire host build, thus saving time and resources.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If security measures are implemented for component replacement, then authentication is secured, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management controller is designed as a universal component that handles authentication for multiple different components (NVMe SSDs, storage devices, etc.) using a standardized key management approach. This multi-functionality provides strong security without proportionally increasing complexity, as the same controller serves multiple security needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12613970B2Seamless and secured device startup after device part replacement
Publication Date: 2026.04.28 DELL PROD LP
  • US12613970B2 patent drawing
  • US12613970B2 patent drawing
  • US12613970B2 patent drawing

AI summary

Methods and systems for managing device startup are disclosed. Device keys used by boot up components of a data processing system to access one or more hardware and/or software components of the data processing system may be maintained by an entity installed within the data processing system that operates independently of a main processor of the data processing system. New and/or replacement device keys may be obtained by said entity while the data processing system is in a powered off state such that when the data processing system is later powered on, the boot up components will have access to the new and/or replacement device keys to effectuate a seamless boot up of the data processing system using newly installed ones of the one or more hardware and/or software components.