Hardware Management Controller for Unmanaged Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional computer systems face challenges in managing and securing unmanaged devices within networks, as they often lack installed agents, making it difficult to detect, communicate with, and enforce security policies, leading to potential security threats and vulnerabilities.
Innovation Solution
Implementing hardware-based management controllers that generate secure identifiers and provide out-of-band management capabilities, allowing for secure communication and policy enforcement independent of the operating system, and enabling remote access to security data and operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based agents are installed on devices to enable management and security tasks, then the ability to inspect and control devices is improved, but the dependency on the operating system and installed agent increases, making unmanaged devices insecure and difficult to control
Solution Approach 1:
The patent divides the management system into two independent components: a hardware-based management controller embedded in the device and a separate management server. This segmentation allows the management controller to operate independently of the operating system and software agents, providing reliable security enforcement even when the OS is compromised or unavailable.
Solution Approach 2:
The hardware-based management controller acts as an intermediary between the device and the management server. It provides a trusted communication channel that does not rely on software agents or the operating system, enabling secure policy enforcement and device inspection for both managed and unmanaged devices.
2Productivity
If traditional software-based management is used, then managed devices can be inspected and controlled, but unmanaged devices without installed agents cannot be detected or secured, creating security vulnerabilities
Solution Approach 1:
The hardware-based management controller provides universal management capabilities that work with all devices regardless of their software configuration. It can detect, communicate with, and enforce security policies on both managed devices with agents and unmanaged devices without agents, making the system adaptable to diverse device states.
Solution Approach 2:
The management controller enables unmanaged devices to self-identify and self-describe their attributes to the management server through hardware-based communication. This allows the server to detect and inspect unmanaged devices without requiring pre-installed software agents, improving both detection efficiency and compatibility.
3Ease of operation
If management depends on the operating system and installed agents, then software-based control is achieved, but security is compromised when the OS or agent is compromised or unavailable
Solution Approach 1:
The patent separates management functionality from the operating system by embedding a hardware-based management controller that operates independently. This allows security-critical operations to be performed through the controller rather than through vulnerable software layers, maintaining reliability even when the OS is compromised.
Solution Approach 2:
The hardware-based management controller provides a pre-established trusted communication channel that cushions against OS vulnerabilities. By having this independent hardware layer in place before any software compromise occurs, the system maintains security enforcement capability even when software agents are compromised or unavailable.
Data Source
AI summary
An opportunity for a computing device to participate in a secure session with a particular domain is identified. A secured microcontroller of the computing device is used to identify a secured, persistent seed corresponding to the particular domain and stored in secured memory of the computing device. A secure identifier is derived based on the seed and sent for use by the particular domain in authenticating the computing device to the particular domain for the secure session. The particular domain can further apply security policies to transactions involving the computing device and particular domain based at least in part on the secure identifier.


