Modular Edge Data Center Autonomous Security Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modular data centers (MDCs) deployed in remote locations are vulnerable to physical threats due to delayed human intervention, risking hardware loss and compromising sensitive workloads and data, especially when there is a loss of communication with an external data center.

Innovation Solution

A security system within the MDC, featuring a controller communicatively coupled to IT components and an in-band communication network, monitors for communication losses indicative of unauthorized access. In response, it secures IT components by encrypting storage media and disabling physical communication ports to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MDCs are deployed in remote locations to extend network edge, then service coverage and accessibility are improved, but vulnerability to physical threats increases due to delayed human intervention

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by monitoring communication channels for signs of intrusion before physical access is gained. The loss of communication or unauthorized communication attempts trigger pre-configured security responses, allowing the system to prepare defenses in advance of the actual physical breach.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The MDC implements self-service security mechanisms that autonomously detect threats and execute countermeasures without human intervention. The system monitors its own communication channels, detects anomalies, and automatically implements security protocols, enabling remote units to protect themselves independently.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If human intervention response time is extended in remote locations, then operational autonomy is improved, but the window for unauthorized access increases

Engineering Contradiction:
Improveoperational autonomyVSAvoidunauthorized access window
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system establishes continuous feedback loops through monitoring communication channels between the MDC and external networks. Any deviation from normal communication patterns immediately feeds back to the security controller, which then triggers appropriate countermeasures, creating a closed-loop security system that responds in real-time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies preliminary anti-action by detecting communication anomalies that precede physical intrusion and automatically implementing security countermeasures before the unauthorized person can gain physical access. This preemptive approach neutralizes threats before they can materialize into actual breaches.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If security measures are strengthened to prevent physical access, then security protection is improved, but system complexity and intervention time increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication monitoring system serves as an intermediary that detects threats at a distance before they reach the physical security perimeter. By placing sensors and monitors in the communication path rather than relying solely on physical barriers, the system extends security detection capability without adding complex physical security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If physical security barriers are enhanced to prevent intruder access, then security protection is improved, but response time for legitimate operations decreases

Engineering Contradiction:
Improvesecurity protectionVSAvoidlegitimate operation response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and authorization checks through communication channels before allowing physical access or operations. By verifying credentials and authorizing operations remotely in advance, the system eliminates the need for time-consuming on-site security checks for legitimate users while maintaining strong security barriers.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10779432B1Modular edge data center that autonomously secures information technology components, computing workload, and data in response to unexpected loss of communication
Publication Date: 2020.09.15 DELL PROD LP
  • US10779432B1 patent drawing
  • US10779432B1 patent drawing
  • US10779432B1 patent drawing

AI summary

A modular data center (MDC) has information technology (IT) component(s) positioned within an interior enclosure of a volumetric container of the MDC. An in-band communication network connection is between the IT component(s) and a data center external to the MDC. A security system includes a controller that is communicatively coupled to the IT component(s) and the in-band communication network connection. The controller executes a security platform application that enables the MDC to secure the IT component(s). The controller monitors the in-band communication network connection for a loss in communication that can be indicative of a preparatory act by an unauthorized person to compromise the IT component(s) or access computing workload and/or data. In response to determining that the in-band communication network connection is not operable, the controller autonomously secures the IT component(s), computing workload, and data by removing a locking key of a storage device to encrypt storage media.