Authentication-Free Service Controller Configuration via IPMI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current out-of-band management systems for high-density server systems face inefficiencies due to complex authentication processes required for credential management, which increase verification delays and reduce the ability to manage large numbers of service controllers effectively.

Innovation Solution

Implementing an authentication-free protocol using Intelligent Platform Management Interface (IPMI) over Inter-Integrated Circuit (I2C) to enable a primary service controller to configure multiple secondary service controllers with the same credentials, eliminating the need for complex authentication and allowing efficient credential management across multiple service controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication protocols are used for credential management between service controllers, then security requirements are met, but verification delays increase and management efficiency decreases

Engineering Contradiction:
Improvesecurity requirementsVSAvoidverification delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the communication channel into two distinct paths: an authenticated path for initial credential establishment and an authentication-free path for subsequent configuration transfers. This segmentation allows security to be maintained for critical authentication operations while enabling efficient unauthenticated communication for routine configuration management, thereby resolving the contradiction between security requirements and verification delays.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication to establish shared credentials between the primary service controller and secondary service controllers before configuration transfer. This preliminary action ensures security requirements are met upfront, and subsequent configuration communications can proceed without repeated authentication overhead, thus eliminating verification delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If complex authentication processes are implemented for credential management, then security is enhanced, but device complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into a one-time initial authentication phase and a subsequent configuration transfer phase. The initial phase establishes shared credentials securely, while the configuration phase uses these pre-established credentials without requiring complex real-time authentication, thereby reducing operational difficulty and process complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent copies the same shared credentials from the primary service controller to multiple secondary service controllers through the authentication-free communication path. This copying mechanism simplifies credential management compared to individual authentication processes for each controller, reducing both device complexity and operational difficulty while maintaining security through consistent credential distribution.

Inventive Principle:
Principle #26Copying

3Reliability

If individual credential management is used for each service controller, then security is maintained, but scalability and management efficiency decrease

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges credential management by establishing a single shared credential set that is distributed to multiple secondary service controllers through the authentication-free path. This merging approach maintains security through centralized credential control while dramatically improving scalability and management efficiency, as configuration changes can be propagated to multiple controllers simultaneously without individual authentication overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared credentials serve multiple functions: they authenticate the initial connection, enable subsequent authentication-free communication, and provide a unified identity for group credential management. This multi-functionality allows a single credential set to manage multiple service controllers efficiently, improving productivity and scalability while maintaining security through the universal credential mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10404690B2Authentication-free configuration for service controllers
Publication Date: 2019.09.03 QUANTA COMPUTER INC
  • US10404690B2 patent drawing
  • US10404690B2 patent drawing
  • US10404690B2 patent drawing

AI summary

Embodiments generally relate to out-of-band management of a computing system. The present technology discloses enable a primary service controller to provide a centralized configuration of multiple secondary service controllers so that they can share a same configuration. It can utilize an authentication-free protocol to modify and manage credentials for a large number of service controllers.