Management Controller Virtual Entity Code Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuration data for virtual entities in computing devices is often stored in insecure locations, making them vulnerable to unauthorized access and modification, which can lead to compromised functionality or data theft.

Innovation Solution

A management controller separate from the processor is used to validate program codes and unlock access to configuration data only after successful validation, ensuring secure access and preventing unauthorized access prior to validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration data is stored in accessible locations for virtual entities, then ease of operation is improved, but security is worsened due to vulnerability to unauthorized access and modification

Engineering Contradiction:
Improveaccess to configuration dataVSAvoidunauthorized access and modification
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs validation of program codes associated with virtual entities before allowing access to configuration data. This preliminary validation action ensures that only authorized virtual entities can access their configuration data, resolving the contradiction by establishing security checks prior to access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism that mediates between the virtual entities and the configuration data storage. This intermediary layer verifies program codes and controls access, allowing configuration data to be stored in accessible locations while preventing unauthorized access through the validation filter.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If configuration data is stored in secure locations, then security is improved, but ease of operation is worsened due to restricted access

Engineering Contradiction:
Improveprotection from unauthorized accessVSAvoidaccess to configuration data
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary validation of program codes before restricting access to configuration data. This ensures that the restriction mechanism is intelligent and context-aware, allowing easy access for authorized entities while maintaining security, thus resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control mechanism is dynamic rather than static. It adapts access permissions based on the validation results of program codes, allowing the system to be secure by default while providing easy access when conditions are met. This dynamic approach resolves the contradiction by making access characteristics changeable based on authorization status.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If validation of program codes is implemented, then security is improved, but device complexity is worsened due to additional validation mechanisms

Engineering Contradiction:
Improveprevention of unauthorized accessVSAvoidvalidation mechanism structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The validation mechanism is designed to be universal, serving multiple functions: it validates program codes, controls access to configuration data, and ensures security. By making the validation mechanism multi-functional, the patent reduces the need for separate dedicated components, thereby limiting the increase in device complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-validation of program codes associated with virtual entities. Each virtual entity's program codes are validated against stored validation data, allowing the system to authenticate and control access without requiring complex external validation infrastructure. This self-service approach minimizes additional complexity while achieving security goals.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11537732B2Unlocking access of information responsive to validation of program codes of virtual entities
Publication Date: 2022.12.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11537732B2 patent drawing
  • US11537732B2 patent drawing
  • US11537732B2 patent drawing

AI summary

In some examples, a management controller includes a communication interface to communicate with a computing device, where the management controller is separate from a processor of the computing device. The management controller includes a management processor to perform a validation of program codes of virtual entities of the computing device, and in response to the validation of the program codes, unlock access of information in an information store to allow access of the information by the computing device, wherein the information is for use by the virtual entities of the computing device, and wherein the management processor is to block access of the information in the information store prior to the validation.