Location-Aware Cloud Provisioning with Certificate Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing bare metal provisioning methods struggle with determining the actual physical location of customer-ordered devices in cloud environments, which is crucial for compliance and privacy, and lack effective verification of device location during onboarding.
Innovation Solution
Implementing a location-aware policy using a remote access controller hardware component to verify the actual location of devices through a network port authentication protocol, ensuring that the device's claimed location matches the stored location in a certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional bare metal provisioning methods are used, then device onboarding is simplified, but location verification capability is lost
Solution Approach 1:
The system performs preliminary actions by pre-storing the expected physical location in a certificate before the onboarding process. During onboarding, the system automatically compares the claimed location against this pre-stored location without requiring manual verification, thus achieving precise location verification while keeping the onboarding process simple.
Solution Approach 2:
The patent introduces a certificate as an intermediary element that contains the expected location information. This certificate acts as a mediator between the provisioning system and the remote computer, enabling automatic location verification without adding manual steps to the onboarding process.
2Reliability
If location verification is implemented, then compliance and security are improved, but onboarding time increases
Solution Approach 1:
The system performs self-service by automatically comparing the claimed location against the pre-stored location in the certificate without requiring manual intervention. The verification process is automated and occurs in the background during the onboarding flow, ensuring reliable location verification while minimizing time loss.
Solution Approach 2:
The patent replaces manual location verification mechanisms with an automated cryptographic comparison system. Instead of manual checking, the system uses certificate-based automated verification that compares location data programmatically, improving reliability while reducing time consumption.
3Extent of automation
If manual location verification is used, then verification accuracy is maintained, but system automation is reduced
Solution Approach 1:
The patent replaces manual verification mechanisms with an automated cryptographic comparison system. The system automatically extracts location information from the claimed location and compares it against the pre-stored location in the certificate using cryptographic validation, achieving both high automation extent and verification accuracy.
Solution Approach 2:
The certificate serves as an intermediary that enables automated verification. It contains the expected location information in a machine-readable format that can be automatically compared against claimed locations, thus achieving full automation while maintaining verification accuracy through cryptographic validation.
Data Source
AI summary
A system can receive an untrusted onboard announcement message from a remote computer. The system can, based on the untrusted onboard announcement message, initiate an onboarding service policy to verify a device location claims policy associated with the remote computer. The system can receive an indication of a remote access controller hardware component of the remote computer, wherein the indication is of verifying a network port authentication policy applicable to determine whether a port-based network access control protocol certificate hostname that is associated with the remote computer matches an entity attestation token attribute extensible authentication protocol-transport layer platform certificate hostname of the remote access controller hardware component to determine a network authentication status. The system can determine whether device onboard location is successful based on a device location verification policy status and the indication.


