Dynamic Primary Node Selection for Multi-Node System Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-node computer systems, existing technologies do not efficiently manage and enforce consistent security settings across nodes, potentially reducing security levels when nodes with different BIOS versions and settings are interconnected, requiring manual updates on the primary node.

Innovation Solution

A method to identify a node within the multi-node system that meets specific security criteria, such as the highest or minimum security setting, and boot the system with that node as the primary, ensuring all nodes operate with the selected security settings, using Trusted Platform Modules and field-programmable gate arrays to dynamically select and configure the primary node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates are performed on the primary node to change BIOS version or security settings, then the desired security configuration is achieved, but system downtime increases and operational complexity increases

Engineering Contradiction:
Improvesecurity configurationVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically selects the primary node based on security settings without requiring manual intervention. The management module autonomously evaluates security criteria and designates the appropriate node, eliminating the need for operators to manually update BIOS or security settings on specific nodes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The primary node designation is made dynamic rather than static. The system can automatically switch the primary node based on security settings, allowing the role to change dynamically in response to security requirements without manual reconfiguration or system downtime.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If the primary node is manually designated, then system configuration is simplified, but security settings may be reduced when nodes with different BIOS versions and settings are interconnected

Engineering Contradiction:
Improvesystem configurationVSAvoidsecurity setting consistency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The management module continuously monitors and evaluates the security settings of all nodes, using this feedback to automatically determine which node should serve as the primary node. This ensures that the system consistently selects the node with the most appropriate security configuration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the selection criterion for the primary node from static manual designation to dynamic security-based evaluation. By evaluating security parameters automatically, the system ensures that the primary node always has the appropriate security settings without increasing configuration complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If BIOS updates are performed on the primary node to change security settings, then security configuration is updated, but update time and system operational disruption increase

Engineering Contradiction:
Improvesecurity settingVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables dynamic switching between primary and secondary nodes based on security settings. When a node needs security updates, the system can dynamically designate a different node as primary, allowing updates to proceed without disrupting overall system availability and productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary evaluation of security settings across all nodes before designating the primary node. This preliminary assessment ensures that the selected primary node already has the appropriate security configuration, eliminating the need for disruptive updates during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9766900B2Booting a multi-node computer system from a primary node dynamically selected based on security setting criteria
Publication Date: 2017.09.19 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9766900B2 patent drawing
  • US9766900B2 patent drawing
  • US9766900B2 patent drawing

AI summary

A method includes identifying, from among nodes within a multi-node system, a node that has a security setting satisfying a security setting criteria, booting the multi-node system with the identified node as the primary node, and operating the multi-node system using the security setting of the identified node. Accordingly, the method may provide dynamic selection of a primary node based upon the security setting criteria and the security settings of the nodes within the multi-node system. Optionally, the security setting of each node is stored in a trusted platform module. In non-limiting examples, the security setting criteria may be the highest security setting among all nodes within the multi-node system or a predetermined minimum security setting, such as a trusted execution technology setting.