Flexible Computing Client for Preboot Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in providing efficient and secure user authentication, especially with resource-intensive operating systems that take long to boot and present security exposures, and require configurations that vary based on user parameters and network conditions.

Innovation Solution

A flexible computing client is implemented for preboot authentication, embedded in non-volatile memory, using a trusted computing module and processor memory protection mechanisms, allowing instant-on user experience and secure boot processes, and can operate in various configurations based on user, device, and network conditions, including virtual machine environments and remote desktop protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a resource-intensive operating system is booted to provide multiple computing roles, then the system can handle diverse computing tasks, but the boot time increases significantly and security exposures occur

Engineering Contradiction:
Improvecomputing role flexibilityVSAvoidboot time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the computing system into multiple distinct operating systems (service OS, application OS, local OS) that can be independently loaded and executed. This allows the system to boot only the necessary OS for the current computing role rather than loading a resource-intensive general-purpose OS, thereby reducing boot time while maintaining versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication and OS selection before the main computing workload begins. The service OS performs user authentication and determines the appropriate application OS to load based on user credentials and computing requirements, allowing the system to prepare and boot only the necessary components in advance, reducing overall boot time.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If a resource-intensive operating system is booted to provide multiple computing roles, then the system can handle diverse computing tasks, but security exposures increase

Engineering Contradiction:
Improvecomputing role flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the system into isolated operating system environments (service OS, application OS, local OS) with distinct security contexts. Each OS runs in its own protected memory space, preventing security vulnerabilities in one OS from affecting others. This segmentation maintains computing versatility while improving security through isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service OS acts as an intermediary between the user and the application OS, performing authentication and authorization before allowing access to computing resources. This intermediary layer enforces security policies and controls which application OS is loaded based on user credentials, thereby improving security while maintaining system versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional personal computer clients are used, then local storage and processing are available, but the system cannot easily adapt to different computing roles and network conditions

Engineering Contradiction:
Improvelocal processing capabilityVSAvoidcomputing role flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal computing platform that can function as multiple types of clients (diskless client, remote desktop client, KVMoIP client, etc.) by loading different application OS images over the network. The service OS manages this universality by selecting and loading the appropriate application OS based on user credentials and computing requirements, allowing a single hardware platform to perform multiple client functions while maintaining local processing capability through the embedded service OS.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If diskless clients, remote desktop clients, or KVMoIP clients are used, then computing resource flexibility is improved, but local processing capability and storage are reduced

Engineering Contradiction:
Improveclient type flexibilityVSAvoidlocal processing capability
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the computing functions into network-based services (provided by remote servers for diskless, remote desktop, and KVMoIP clients) and local embedded services (provided by the service OS). This segmentation allows the system to leverage network resources for storage and application execution while maintaining local processing capability for authentication, session management, and protocol handling, thereby achieving client flexibility without completely sacrificing local processing capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8001581B2Methods and systems for embedded user authentication and/or providing computing services using an information handling system configured as a flexible computing node
Publication Date: 2011.08.16 DELL PROD LP
  • US8001581B2 patent drawing
  • US8001581B2 patent drawing
  • US8001581B2 patent drawing

AI summary

Methods and systems for providing embedded user authentication and/or providing computing services using an information handling system configured as flexible computing node, and which may be implemented to perform preboot authentication of users. The flexible computing node may also be configured to provision the appropriate work environment for a given user based on one or more user parameters (e.g. entitlements, location, network connection, and/or other parameters).