Lights-Out Management Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for lights-out management (LOM) and out-of-band (OOB) management lack efficient authentication mechanisms that allow authorized users to access and operate devices remotely, especially when the device is powered down, and do not seamlessly integrate with applications requiring user authentication like Secure Shell (SSH) protocols.

Innovation Solution

A system that utilizes non-volatile data storage to store and retrieve LOM credentials, enabling remote access and authentication even when the device is shut down, by comparing user-provided authentication data with stored credentials, and sharing these credentials with applications running under an operating system for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms are used for LOM remote access, then device security is maintained, but authentication efficiency and integration with applications like SSH are insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication mechanism where LOM credentials serve dual purposes: authenticating users for LOM remote access and authenticating users for applications running under the operating system (such as SSH). This eliminates the need for separate authentication systems, improving efficiency while maintaining security through a single integrated credential store in non-volatile memory.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Use of energy by moving object

If device is powered down for energy saving, then energy consumption is reduced, but remote access capability is lost

Engineering Contradiction:
Improveenergy consumptionVSAvoidremote access capability
Core Design Contradiction:
Use of energy by moving objectVSEase of operation

Solution Approach 1:

The patent segments the authentication functionality into two independent parts: the LOM credential storage in non-volatile memory remains active and accessible even when the main device is powered down, while the operating system and applications can be independently managed. This allows the authentication mechanism to function during power-down states for LOM access while maintaining the ability to power on the device for application execution.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If credentials are stored in non-volatile memory for LOM access, then remote access is enabled when device is shut down, but credential security management becomes more complex

Engineering Contradiction:
Improveremote access availabilityVSAvoidcredential management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the LOM credential storage with the existing non-volatile memory infrastructure of the device, rather than creating a separate secure storage system. This integration leverages the existing memory architecture to store authentication credentials, simplifying the overall system design while enabling remote access capability during power-down states through the same storage medium.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9218462B2Authentication using lights-out management credentials
Publication Date: 2015.12.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9218462B2 patent drawing
  • US9218462B2 patent drawing
  • US9218462B2 patent drawing

AI summary

A method includes upon receiving a request from a user to perform an operation on a device that is running under an operating system, authenticating the user on the basis of credential data that is retrieved from a data storage unit that is associated with a lights-out management (LOM) capability of the device. If authentication of the user is successful, the user is enabled to perform the operation.