Network Boot Storage Authentication via Dynamic Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network boot systems, unauthorized access to storage units can occur due to static authentication information, data inconsistencies arise from simultaneous log-ins, and maintenance costs are high due to the need for multiple logical units per user.
Innovation Solution
An administration server authenticates clients and users, generates dynamic passwords for individual storage units, and manages access through a database, allowing only approved access while reducing the need for multiple units by using replica storage units for maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static authentication information is used for storage unit access, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent implements dynamic authentication information that changes over time or based on conditions. Instead of static passwords, the system uses authentication information that is generated and updated dynamically, making it difficult for unauthorized users to gain access while maintaining ease of operation for authorized users.
Solution Approach 2:
The authentication parameters are changed dynamically rather than remaining static. The system modifies authentication information based on various parameters such as time, user identity, or access patterns, thereby enhancing security while preserving operational simplicity through automated parameter management.
2Reliability
If multiple logical units are prepared for each user, then data consistency is improved, but maintenance cost increases
Solution Approach 1:
The patent merges multiple logical units into a unified structure where data consistency is maintained through centralized control mechanisms. Instead of managing separate logical units independently, the system combines them under a single management framework that ensures consistency across all units while reducing the complexity of maintenance operations.
Solution Approach 2:
The logical units are designed with universal management capabilities that allow a single maintenance operation to affect multiple units simultaneously. This multi-functionality enables administrators to perform maintenance tasks on all logical units through a unified interface, reducing overall maintenance complexity while maintaining data consistency across the system.
3Adaptability or versatility
If the same user logs in from multiple client terminals simultaneously, then adaptability is improved, but data consistency deteriorates
Solution Approach 1:
The patent implements feedback mechanisms that monitor and coordinate simultaneous logins from multiple client terminals. The system provides real-time feedback to each terminal about the state of other connections, enabling the user to maintain data consistency across multiple terminals while preserving the adaptability of multi-terminal access.
Solution Approach 2:
An intermediary mechanism is introduced to manage simultaneous user sessions across multiple client terminals. This mediator coordinates access between terminals, ensuring that data consistency is maintained while allowing the user to adaptively access the system from multiple locations or devices.
4Ease of operation
If authentication information is statically assigned, then ease of operation is improved, but vulnerability to leakage increases
Solution Approach 1:
The patent replaces static authentication information with dynamic credentials that automatically change or expire. This dynamic approach maintains ease of operation through automated credential management while significantly reducing vulnerability to information leakage, as compromised credentials become invalid over time or after a single use.
Solution Approach 2:
The authentication information is designed as a disposable or short-lived credential rather than a permanent static password. Each authentication token has a limited lifespan or single-use property, making it economically and security-wise advantageous to generate new credentials frequently, thereby reducing the impact of any potential leakage while maintaining operational simplicity.
Data Source
AI summary
A network boot system including one or more client terminals, a DHCP (Dynamic Host Configuration Protocol) server, a PXE (Preboot Execution Environment) server, a TFTP (Trivial File Transfer Protocol) server, a database administration server, one or more storage devices, and an authentification server (such as a Radius server) connected to each other via a TCP/IP (Transmission Control Protocol)/Internet Protocol) network. A plurality of LU provided in the storage devices as separated into a system area LU and a user area LU prepared per user.


