Modular Data Center Workload Migration for Physical Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modular data centers (MDCs) deployed in remote locations are vulnerable to physical intrusions, which can compromise sensitive workloads and data, as malicious individuals can gain access before human intervention can occur, putting at risk both the local MDC and network-connected systems.

Innovation Solution

A security system that includes sensors to detect unauthorized persons, a personnel authentication device to verify authorized access, and a controller that executes a security platform application to transfer computing workloads and data to a secure external data center via an in-band communication network connection in case of an unauthorized presence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MDCs are deployed in remote locations to extend network edge, then service coverage and accessibility are improved, but vulnerability to physical intrusions increases

Engineering Contradiction:
Improveservice coverageVSAvoidphysical intrusion vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication of personnel before allowing access to workloads and data. Sensors detect presence and the authentication device verifies credentials in advance, so that by the time an intruder attempts to access sensitive information, the system has already identified the threat and initiated protective actions by transferring workloads to secure locations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication device and controller that stand between the intruder and the sensitive workloads/data. This intermediary layer verifies credentials and mediates access requests, preventing direct access to the MDC resources even when physical access to the location is obtained.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional security monitoring is used, then detection capability is provided, but response time is too slow to prevent intruder access

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security system is self-service in that it automatically detects intrusions via sensors, authenticates personnel credentials, and transfers workloads to secure locations without requiring human intervention. This automated response chain eliminates the time delay associated with human reaction, enabling the system to protect itself in real-time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback through sensors that monitor the MDC environment. When an intrusion is detected, the feedback loop triggers immediate authentication verification and subsequent workload transfer actions, creating a closed-loop security response that adapts to threats in real-time rather than relying on periodic or manual checks.

Inventive Principle:
Principle #23Feedback

3Speed

If workload and data remain in the MDC for quick access, then service speed is improved, but exposure to physical threats increases

Engineering Contradiction:
Improveservice speedVSAvoidexposure to physical threats
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts the location of workloads based on security conditions. During normal operation, workloads remain local in the MDC for fast access. When threats are detected, the system dynamically migrates workloads to remote secure locations, and can restore them when threats are eliminated. This dynamic adaptation allows the system to maintain speed when safe while protecting against threats when necessary.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system takes preliminary anti-action by proactively transferring workloads to secure locations before an intruder can compromise them. Rather than reacting after damage occurs, the system anticipates the threat by monitoring authentication status and preemptively relocating sensitive workloads when unauthorized access is detected, thereby preventing the harmful effect before it can manifest.

Inventive Principle:
Principle #9Preliminary anti-action

4Reliability

If comprehensive authentication and sensor monitoring are implemented, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The controller serves multiple functions: it manages normal MDC operations, receives sensor data, processes authentication credentials, decides when threats exist, and executes workload transfer commands. By consolidating these diverse functions into a single multi-functional controller, the system achieves comprehensive security monitoring and response capabilities without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11218458B2Modular data center that transfers workload to mitigate a detected physical threat
Publication Date: 2022.01.04 DELL PROD LP
  • US11218458B2 patent drawing
  • US11218458B2 patent drawing
  • US11218458B2 patent drawing

AI summary

A modular data center (MDC) includes an in-band communication network connection communicatively coupled between an information technology (IT) component of the MDC and a data center external to the MDC. A sensor of a security system of the MDC detects a presence of a person in proximity to an exterior of the MDC or inside of the MDC. In response to determining that the person is detected, a controller of the MDC determines whether the detected person is authenticated. In response to determining that the detected person is not authenticated, the controller authenticates the data center via the in-band communication network connection, and the controller transfers computing workload and data from the at least one IT component to the data center via the in-band communication network connection.