IHS Secure Delivery Validation via Shipping Certificate Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) are vulnerable to tampering through compromised external devices, where malicious actors can intercept or add compromised devices during shipment, compromising the security of the system by administrators unknowingly connecting these devices.

Innovation Solution

The implementation of a method that involves retrieving and comparing shipping identifiers from received packages against a shipping certificate uploaded during factory provisioning to validate the secure delivery of IHS components and additional items, using pre-boot validation processes and persistent memory storage, ensuring only trusted packages are connected to the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If shipping identifiers are collected and compared against a shipping certificate to validate package authenticity, then security against compromised external devices is improved, but the complexity of the validation process increases

Engineering Contradiction:
ImprovesecurityVSAvoidvalidation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The shipping certificate is generated and stored in persistent memory during factory provisioning before the IHS is shipped to the customer. This preliminary action ensures that the reference data for validation is already in place, eliminating the need for complex real-time certificate generation and reducing validation complexity when packages are received.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a shipping certificate as an intermediary data structure that mediates between the factory provisioning process and the customer's validation process. This certificate contains pre-collected shipping identifiers and serves as a trusted reference, simplifying the validation process by providing a clear comparison basis without requiring complex authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a pre-boot validation process is implemented to compare shipping identifiers, then detection of tampered packages is improved, but the time required for system initialization increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidinitialization time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The validation process focuses on comparing only the essential shipping identifiers from the received packages against the pre-stored shipping certificate, rather than performing a comprehensive validation of all system components. This partial action approach maintains detection accuracy for package tampering while minimizing the time added to system initialization.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If shipping identifiers are stored in persistent memory during factory provisioning, then validation of received packages is improved, but the manufacturing process complexity increases

Engineering Contradiction:
Improvepackage validation reliabilityVSAvoidfactory provisioning complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the collection of shipping identifiers with the existing factory provisioning process. The shipping certificate is generated and stored in persistent memory as part of the standard provisioning workflow, combining multiple functions (identifier collection, certificate generation, and storage) into a single integrated process that leverages existing manufacturing infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11928639B2Validating secure delivery of information handling systems
Publication Date: 2024.03.12 DELL PROD LP
  • US11928639B2 patent drawing
  • US11928639B2 patent drawing
  • US11928639B2 patent drawing

AI summary

Embodiments provide methods for validating secure delivery of an IHS (Information Handling System) by confirming that the packages by which the IHS was delivered include only the packages used to ship the IHS from a factory or other trusted entity. During factory provisioning of the IHS, a shipping certificate is uploaded to the IHS, where the certificate includes shipping identifiers that are each associated with a package used to ship the IHS. Upon receiving packages by which the IHS has been shipped, shipping identifiers, such as bar codes and RFID codes, are collected from the received packages. The shipping identifiers collected from the received packages are compared against the shipping identifiers from the shipping certificate in order to validate the plurality of received packages as the same packages that were used to ship the IHS.