IHS Subsystem Vulnerability Proofing via Remote Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face vulnerabilities due to varying configurations and updates, which can lead to security and functional issues, especially when administrators are unaware of known vulnerabilities in hardware and software components.

Innovation Solution

Implementing a remote access controller that detects configuration changes, accesses catalogs of known vulnerabilities, and disables subsystems until all components are updated to secure versions, ensuring no vulnerabilities are present, using factory-provisioned identity certificates and digital signatures for authentication and validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators update hardware and software configurations to improve functionality and adapt to changing requirements, then the system becomes more versatile and adaptable, but known vulnerabilities in configurations are introduced that can be exploited by malicious actors

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidvulnerability to exploitation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary vulnerability assessment by checking proposed configurations against vulnerability catalogs before applying changes. The remote access controller intercepts configuration requests, evaluates them against known vulnerabilities in advance, and only permits changes that pass security validation, preventing vulnerable configurations from being deployed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where configuration changes are monitored, vulnerability assessments are performed, and alerts are generated when vulnerabilities are detected. This feedback mechanism enables administrators to receive notifications about vulnerable configurations and take corrective actions, creating a closed-loop security management system.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple administrators configure servers according to changing policies throughout the server lifetime, then the system adapts to different operational requirements, but inconsistent configuration practices increase vulnerability risk

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidconfiguration consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The remote access controller serves multiple functions: it acts as a management interface for administrators, a vulnerability assessment engine, a configuration validator, and an enforcement mechanism. This universal controller ensures that regardless of which administrator makes changes or what policies are applied, all configurations undergo the same vulnerability assessment and validation process, ensuring consistent security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts configuration parameters by comparing proposed changes against vulnerability catalogs. When vulnerabilities are detected, the system automatically modifies configuration parameters to avoid vulnerable settings while maintaining functional requirements, ensuring that policy changes do not introduce security risks.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If vulnerability catalogs are continuously accessed and checked to prevent known vulnerabilities, then security is improved, but system complexity and administration overhead increase

Engineering Contradiction:
Improvevulnerability preventionVSAvoidadministration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The remote access controller automatically performs vulnerability assessments against continuously updated catalogs without requiring manual administrator intervention. The system self-manages the complexity of maintaining vulnerability databases, performing assessments, and enforcing security policies, freeing administrators from manual security checking while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The remote access controller acts as an intermediary layer between administrators and the vulnerable hardware configurations. It absorbs the complexity of vulnerability management by intercepting configuration requests, performing automated assessments against vulnerability catalogs, and enforcing security policies, thereby shielding administrators from the complexity of manual vulnerability management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If the entire IHS subsystem is disabled when a vulnerability is detected in any component, then security is ensured by preventing vulnerable configurations, but system availability and productivity decrease

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem availability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system segments the IHS into independent subsystems and applies vulnerability management at the component level rather than system-wide. When a vulnerability is detected in a specific hardware component or software module, only that particular component is restricted or rolled back, while other unaffected subsystems continue to operate normally, maintaining overall system availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The remote access controller applies security measures locally to specific vulnerable components rather than globally to the entire system. Configuration changes and vulnerability remediations are targeted at individual hardware components, software modules, or subsystems based on where vulnerabilities are detected, allowing healthy portions of the system to maintain full functionality while problematic areas are addressed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12130931B2Systems and methods for vulnerability proofing interdependent IHS components
Publication Date: 2024.10.29 DELL PROD LP
  • US12130931B2 patent drawing
  • US12130931B2 patent drawing
  • US12130931B2 patent drawing

AI summary

Systems and methods are provided for vulnerability proofing subsystems of hardware components of an IHS (Information Handling System). A request to modify configurations of a hardware component of the IHS is detected. Catalogs specifying known vulnerabilities of hardware components are accessed to determine whether any of the modified hardware configurations are identified as vulnerable in one or more of the catalogs. When vulnerabilities are identified in the modified configurations for the hardware component, other hardware components of the IHS are identified that are interdependent on the hardware component as part of an IHS subsystem. Hardware configurations for any of the hardware components of the subsystem are evaluated for vulnerabilities based on the catalogs. If any vulnerabilities are identified, the IHS subsystem is disabled until the configurations for the hardware component and for the interdependent components of the subsystem are changed to include no configurations with vulnerabilities identified in the catalogs.