Location-Aware Cloud Provisioning with Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing bare metal provisioning methods struggle with determining the actual physical location of customer-ordered devices in cloud environments, which is crucial for compliance and privacy, and lack effective verification of device location during onboarding.

Innovation Solution

Implementing a location-aware policy using a remote access controller hardware component to verify the actual location of devices through a network port authentication protocol, ensuring that the device's claimed location matches the stored location in a certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional bare metal provisioning methods are used, then device onboarding is simplified, but location verification capability is lost

Engineering Contradiction:
Improvelocation verification precisionVSAvoidonboarding process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-storing the expected physical location in a certificate before the onboarding process. During onboarding, the system automatically compares the claimed location against this pre-stored location without requiring manual verification, thus achieving precise location verification while keeping the onboarding process simple.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate as an intermediary element that contains the expected location information. This certificate acts as a mediator between the provisioning system and the remote computer, enabling automatic location verification without adding manual steps to the onboarding process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location verification is implemented, then compliance and security are improved, but onboarding time increases

Engineering Contradiction:
Improvedevice onboarding reliabilityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically comparing the claimed location against the pre-stored location in the certificate without requiring manual intervention. The verification process is automated and occurs in the background during the onboarding flow, ensuring reliable location verification while minimizing time loss.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual location verification mechanisms with an automated cryptographic comparison system. Instead of manual checking, the system uses certificate-based automated verification that compares location data programmatically, improving reliability while reducing time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If manual location verification is used, then verification accuracy is maintained, but system automation is reduced

Engineering Contradiction:
Improveonboarding automation extentVSAvoidlocation verification accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The patent replaces manual verification mechanisms with an automated cryptographic comparison system. The system automatically extracts location information from the claimed location and compares it against the pre-stored location in the certificate using cryptographic validation, achieving both high automation extent and verification accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The certificate serves as an intermediary that enables automated verification. It contains the expected location information in a machine-readable format that can be automatically compared against claimed locations, thus achieving full automation while maintaining verification accuracy through cryptographic validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407667B2Location aware trusted cloud resource provisioning
Publication Date: 2025.09.02 DELL PROD LP
  • US12407667B2 patent drawing
  • US12407667B2 patent drawing
  • US12407667B2 patent drawing

AI summary

A system can receive an untrusted onboard announcement message from a remote computer. The system can, based on the untrusted onboard announcement message, initiate an onboarding service policy to verify a device location claims policy associated with the remote computer. The system can receive an indication of a remote access controller hardware component of the remote computer, wherein the indication is of verifying a network port authentication policy applicable to determine whether a port-based network access control protocol certificate hostname that is associated with the remote computer matches an entity attestation token attribute extensible authentication protocol-transport layer platform certificate hostname of the remote access controller hardware component to determine a network authentication status. The system can determine whether device onboard location is successful based on a device location verification policy status and the indication.