Digital Keyboard for Secure IHS Credential Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems (IHS) face vulnerabilities when service processor credentials are shared with service providers, leading to potential malicious attacks and suboptimal system performance due to hardware and firmware configuration issues during part replacements.
Innovation Solution
A method and system that generates a digital keyboard to autonomously provision security credentials to a second device, enabling secure access and management of IHS functionalities without exposing sensitive information, using a secure digital keyboard utility to establish a unidirectional communication link and write security credentials to an open text editor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of repair
If service processor credentials are shared with service providers to enable hardware serviceability, then ease of repair is improved, but security is worsened due to vulnerability to malicious attacks
Solution Approach 1:
The patent segments the service provider's access capabilities by creating a dedicated service processor image with restricted credentials. This segmented access allows service providers to perform hardware repairs while maintaining security boundaries that prevent malicious attacks on the main system.
Solution Approach 2:
The patent introduces a service processor as an intermediary layer between the service provider and the main system. This intermediary handles service operations with limited credentials, acting as a mediator that enables repair access while protecting the primary system from security threats.
2Ease of operation
If service processor credentials are disclosed to service providers for part replacement, then ease of operation is improved, but security is worsened due to potential malicious attacks
Solution Approach 1:
The patent applies local quality by providing different credential levels to different service providers or service scenarios. The service processor image contains localized security credentials that are tailored to specific service needs, allowing ease of operation for legitimate services while restricting access to prevent malicious attacks.
3Device complexity
If hardware parts are replaced without corresponding firmware upgrades, then device complexity is reduced, but productivity is worsened due to suboptimal system performance
Solution Approach 1:
The patent merges the hardware replacement process with firmware update capabilities by providing a service processor image that includes both the service functionality and firmware update mechanisms. This combined approach allows service providers to perform replacements while automatically or conveniently applying necessary firmware upgrades, maintaining productivity without excessive complexity.
4Device complexity
If older software/firmware settings are used with new hardware, then device complexity is reduced, but reliability is worsened due to hardware deterioration
Solution Approach 1:
The patent applies preliminary action by pre-configuring the service processor image with appropriate firmware settings that are optimized for the specific hardware version. This preliminary preparation ensures that when new hardware is installed, the correct software/firmware settings are automatically applied, preventing hardware deterioration without requiring complex manual configuration.
Data Source
AI summary
A method and data processing device for detecting connection of a second device at an interface of an IHS. The method includes receiving a request to modify at least one secure functionality associated with the IHS, the request comprising identification input. The method includes generating security credentials that correspond to a predetermined level of security that is assigned to the identification input. The method includes triggering the service processor to establish a secure communication link to the second device for communicatively connecting a digitally generated keyboard. The method includes autonomously inputting the security credentials to the digitally generated keyboard. The method includes signaling to the digitally generated keyboard to write the security credentials to the second device for use to obtain access to the IHS according to the predetermined level of security. Based on the predetermined level of security, the method includes enabling management of certain functionalities of the IHS.


