Enclosure Security via Chassis Manager Baseline Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge devices deployed in remote locations face challenges in managing hardware changes and detecting tampering due to reduced physical security, making it difficult to differentiate between authorized and unauthorized modifications, which can impact data integrity and processing.

Innovation Solution

A system and method for managing hardware changes at the enclosure and server levels using a manageability controller and chassis manager, which monitor and compare current hardware configurations to baseline configurations, enabling tamper detection and performing security actions automatically to prevent unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If edge devices are deployed in remote locations to collect and process data, then data collection and processing capability is improved, but physical security and protection against unauthorized hardware changes deteriorates

Engineering Contradiction:
Improvedata collection and processing capabilityVSAvoidphysical security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system enables self-service security monitoring by automatically detecting hardware changes through baseline comparisons and autonomously responding to unauthorized modifications without requiring constant human oversight or manual security interventions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where hardware configurations are monitored, compared against baselines, and security actions are automatically triggered based on detected deviations, creating a closed-loop security mechanism that adapts to changes in real-time

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual monitoring of hardware changes is implemented, then detection accuracy is improved, but operational complexity and response time deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system replaces manual mechanical monitoring processes with automated electronic detection mechanisms that use baseline comparisons and algorithmic analysis to identify unauthorized hardware changes, eliminating the need for human operators to manually inspect and compare hardware configurations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary automated monitoring layer that sits between the hardware and human operators, using baseline configurations as a reference medium to detect and report unauthorized changes, thereby simplifying the operational process while maintaining high detection accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If automated security actions are performed, then response speed is improved, but risk of false positives and unauthorized disruptions worsens

Engineering Contradiction:
Improveresponse speedVSAvoidrisk of false positives
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing baseline hardware configurations before deployment and pre-defining security policies that specify which hardware changes constitute unauthorized modifications, enabling the system to make accurate automated decisions without false positives

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by pre-configuring security policies that define acceptable hardware changes and automatically preventing or reversing unauthorized modifications before they can cause harm, thereby protecting against both actual threats and potential false positives through predefined rules

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11899831B2Managing security of enclosure based on a task status and geographical location of the enclosure
Publication Date: 2024.02.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11899831B2 patent drawing
  • US11899831B2 patent drawing
  • US11899831B2 patent drawing

AI summary

Examples described herein relate to a method for managing hardware changes at an enclosure and a server. The enclosure includes a server and multiple hardware devices connected to the enclosure. A chassis manager in the enclosure is communicatively coupled to a manageability controller of the server and the multiple hardware devices. On enabling tamper detection, the manageability controller and the chassis manager monitor the hardware devices for determining changes in the hardware devices. A change in a hardware device is compared with a permissible hardware change to determine whether the change in the hardware device is unauthorized. The permissible hardware changes include changes in hardware devices that are permitted by a customer. Security actions are performed at the server and the enclosure if unauthorized changes in the hardware device are detected by the manageability controller and chassis manager.