Digital Keyboard for Secure IHS Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems (IHS) face vulnerabilities when service processor credentials are shared with service providers, leading to potential malicious attacks and suboptimal system performance due to hardware and firmware configuration issues during part replacements.

Innovation Solution

A method and system that generates a digital keyboard to autonomously provision security credentials to a second device, enabling secure access and management of IHS functionalities without exposing sensitive information, using a secure digital keyboard utility to establish a unidirectional communication link and write security credentials to an open text editor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If service processor credentials are shared with service providers to enable hardware serviceability, then ease of repair is improved, but security is worsened due to vulnerability to malicious attacks

Engineering Contradiction:
Improvehardware serviceabilityVSAvoidsecurity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent segments the service provider's access capabilities by creating a dedicated service processor image with restricted credentials. This segmented access allows service providers to perform hardware repairs while maintaining security boundaries that prevent malicious attacks on the main system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a service processor as an intermediary layer between the service provider and the main system. This intermediary handles service operations with limited credentials, acting as a mediator that enables repair access while protecting the primary system from security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If service processor credentials are disclosed to service providers for part replacement, then ease of operation is improved, but security is worsened due to potential malicious attacks

Engineering Contradiction:
Improveservice provider accessVSAvoidmalicious attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by providing different credential levels to different service providers or service scenarios. The service processor image contains localized security credentials that are tailored to specific service needs, allowing ease of operation for legitimate services while restricting access to prevent malicious attacks.

Inventive Principle:
Principle #3Local quality

3Device complexity

If hardware parts are replaced without corresponding firmware upgrades, then device complexity is reduced, but productivity is worsened due to suboptimal system performance

Engineering Contradiction:
Improveupgrade processVSAvoidsystem performance
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent merges the hardware replacement process with firmware update capabilities by providing a service processor image that includes both the service functionality and firmware update mechanisms. This combined approach allows service providers to perform replacements while automatically or conveniently applying necessary firmware upgrades, maintaining productivity without excessive complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If older software/firmware settings are used with new hardware, then device complexity is reduced, but reliability is worsened due to hardware deterioration

Engineering Contradiction:
Improvesoftware-hardware configurationVSAvoidhardware durability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring the service processor image with appropriate firmware settings that are optimized for the specific hardware version. This preliminary preparation ensures that when new hardware is installed, the correct software/firmware settings are automatically applied, preventing hardware deterioration without requiring complex manual configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10678956B2Keyboard for provisioning security credentials
Publication Date: 2020.06.09 DELL PROD LP
  • US10678956B2 patent drawing
  • US10678956B2 patent drawing
  • US10678956B2 patent drawing

AI summary

A method and data processing device for detecting connection of a second device at an interface of an IHS. The method includes receiving a request to modify at least one secure functionality associated with the IHS, the request comprising identification input. The method includes generating security credentials that correspond to a predetermined level of security that is assigned to the identification input. The method includes triggering the service processor to establish a secure communication link to the second device for communicatively connecting a digitally generated keyboard. The method includes autonomously inputting the security credentials to the digitally generated keyboard. The method includes signaling to the digitally generated keyboard to write the security credentials to the second device for use to obtain access to the IHS according to the predetermined level of security. Based on the predetermined level of security, the method includes enabling management of certain functionalities of the IHS.