Hardware Management Controller for Unmanaged Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer systems face challenges in managing and securing unmanaged devices within networks, as they often lack installed agents, making it difficult to detect, communicate with, and enforce security policies, leading to potential security threats and vulnerabilities.

Innovation Solution

Implementing hardware-based management controllers that generate secure identifiers and provide out-of-band management capabilities, allowing for secure communication and policy enforcement independent of the operating system, and enabling remote access to security data and operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based agents are installed on devices to enable management and security tasks, then the ability to inspect and control devices is improved, but the dependency on the operating system and installed agent increases, making unmanaged devices insecure and difficult to control

Engineering Contradiction:
Improvedevice management capabilityVSAvoidsecurity enforcement reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the management system into two independent components: a hardware-based management controller embedded in the device and a separate management server. This segmentation allows the management controller to operate independently of the operating system and software agents, providing reliable security enforcement even when the OS is compromised or unavailable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware-based management controller acts as an intermediary between the device and the management server. It provides a trusted communication channel that does not rely on software agents or the operating system, enabling secure policy enforcement and device inspection for both managed and unmanaged devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional software-based management is used, then managed devices can be inspected and controlled, but unmanaged devices without installed agents cannot be detected or secured, creating security vulnerabilities

Engineering Contradiction:
Improvedevice inspection efficiencyVSAvoidcompatibility with unmanaged devices
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The hardware-based management controller provides universal management capabilities that work with all devices regardless of their software configuration. It can detect, communicate with, and enforce security policies on both managed devices with agents and unmanaged devices without agents, making the system adaptable to diverse device states.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The management controller enables unmanaged devices to self-identify and self-describe their attributes to the management server through hardware-based communication. This allows the server to detect and inspect unmanaged devices without requiring pre-installed software agents, improving both detection efficiency and compatibility.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If management depends on the operating system and installed agents, then software-based control is achieved, but security is compromised when the OS or agent is compromised or unavailable

Engineering Contradiction:
Improvesoftware-based control capabilityVSAvoidsecurity posture
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent separates management functionality from the operating system by embedding a hardware-based management controller that operates independently. This allows security-critical operations to be performed through the controller rather than through vulnerable software layers, maintaining reliability even when the OS is compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware-based management controller provides a pre-established trusted communication channel that cushions against OS vulnerabilities. By having this independent hardware layer in place before any software compromise occurs, the system maintains security enforcement capability even when software agents are compromised or unavailable.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11245687B2Hardware-based device authentication
Publication Date: 2022.02.08 MCAFEE LLC
  • US11245687B2 patent drawing
  • US11245687B2 patent drawing
  • US11245687B2 patent drawing

AI summary

An opportunity for a computing device to participate in a secure session with a particular domain is identified. A secured microcontroller of the computing device is used to identify a secured, persistent seed corresponding to the particular domain and stored in secured memory of the computing device. A secure identifier is derived based on the seed and sent for use by the particular domain in authenticating the computing device to the particular domain for the secure session. The particular domain can further apply security policies to transactions involving the computing device and particular domain based at least in part on the secure identifier.