Vulnerability Proofing for IHS Hardware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face vulnerabilities due to inconsistent and unvalidated hardware and software configurations, which can lead to security and functional issues despite intended updates, as administrators may be unaware of known vulnerabilities.

Innovation Solution

Implementing a remote access controller that receives vulnerability proofing requirements, consults catalogs of known vulnerabilities, and validates updates to ensure configurations are secure and compatible with operational workloads, preventing the spread of vulnerabilities across a datacenter.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators update hardware and software configurations to improve system functionality, then system adaptability and productivity are improved, but known vulnerabilities may be introduced causing security risks

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary vulnerability validation on update configurations before deployment. The remote access controller receives vulnerability proofing requirements and validates update configurations against known vulnerability catalogs in advance, preventing vulnerable configurations from being deployed to production systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where vulnerability validation results are returned to the update system. The remote access controller communicates validation outcomes (pass/fail) and vulnerability findings back to the update management system, enabling informed decisions about configuration updates.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive vulnerability validation is performed on all update configurations, then system security is improved, but update deployment time and administrative complexity increase

Engineering Contradiction:
Improvesystem securityVSAvoidupdate deployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and validates only the specific hardware and software configuration parameters that are relevant to vulnerability assessment. The remote access controller receives vulnerability proofing requirements that specify which configuration aspects need validation, rather than performing exhaustive validation on all possible parameters.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the validation approach from exhaustive configuration checking to targeted vulnerability-specific parameter validation. By focusing validation efforts on parameters known to be associated with vulnerabilities (based on vulnerability catalogs), the system achieves adequate security without excessive time consumption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If vulnerability validation requirements are enforced for all updates, then system reliability is improved, but ease of operation deteriorates due to additional validation steps

Engineering Contradiction:
Improvesystem reliabilityVSAvoidupdate administration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service vulnerability validation where the remote access controller automatically receives and processes vulnerability proofing requirements without requiring manual administrator intervention. The validation process is automated, with the system independently checking configurations against vulnerability catalogs and making deployment decisions.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If detailed vulnerability catalogs are consulted for validation, then measurement precision of vulnerability detection is improved, but device complexity increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidvalidation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses vulnerability catalogs as intermediary data structures that store pre-analyzed vulnerability information. Instead of implementing complex vulnerability analysis logic directly in the validation system, the system consults these catalogs which contain structured vulnerability data, configuration patterns, and validation rules prepared by security experts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12135794B2Systems and methods for validated vulnerability proofing
Publication Date: 2024.11.05 DELL PROD LP
  • US12135794B2 patent drawing
  • US12135794B2 patent drawing
  • US12135794B2 patent drawing

AI summary

Systems and methods provided for vulnerability proofing updates to an IHS (Information Handling System). Upon receipt of an update to hardware component configurations of the IHS, vulnerability proofing requirements for modifications to the hardware component configurations are retrieved, including requirements for modifications that are validated for operation of a computational workload by the IHS. Based on the vulnerability proofing requirements, catalogs specifying known vulnerabilities of hardware components are consulted to determine whether the modifications are identified as vulnerable in the catalogs and whether remediations to the identified vulnerabilities are validated for operation of the workload. If the modifications are not identified as vulnerable in the catalogs, the update is transmitted to the IHS. If the modifications are identified as vulnerable in the catalogs and remediations to the identified vulnerabilities are not validated for operation of the workload, the update is terminated.