Information Handling System Network Resource Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems lack effective security measures during initialization, particularly in determining trusted network connections, which can expose devices to security risks when connected to untrusted networks.

Innovation Solution

The method involves determining the WAN IP address during initialization and configuring device resources based on a list of trusted IP addresses, enabling or disabling system interfaces and services accordingly to ensure security, with remedial actions taken when an untrusted network is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device resources are configured to operate in a first state when connected to a trusted network, then system functionality and user experience are improved, but security protection is reduced when connected to untrusted networks

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making device resource configuration dynamic based on network trust status. The system automatically transitions between different operational states (first state for trusted networks, second state for untrusted networks) without manual intervention, allowing full functionality when safe and restricted modes when risky, thus resolving the contradiction between ease of operation and security protection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by continuously monitoring network connection status and using this information to adjust device resource configuration. The system retrieves trusted network information, determines current network trustworthiness, and automatically configures resources accordingly, creating a closed-loop security mechanism that balances functionality and protection

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If device resources are restricted or disabled when connected to untrusted networks, then security protection is improved, but system functionality and user experience deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem functionality
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies local quality by selectively applying security restrictions to specific device resources rather than disabling the entire system. Different resources are configured differently based on their security risk profile - critical resources are restricted while less critical resources may remain functional, allowing nuanced balance between security protection and functionality

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts resource configuration based on real-time network trust assessment. When untrusted networks are detected, the system transitions to a restricted state that applies security measures, and when trusted networks are detected, it transitions to a full-functionality state, making the security-functionality trade-off adaptive rather than static

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If network identification and resource configuration is performed during initialization, then security protection is improved, but initialization time and system startup duration increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidinitialization time
Core Design Contradiction:
Object-affected harmful factorsVSDuration of action of stationary object

Solution Approach 1:

The patent applies preliminary action by performing network identification and trusted network determination during the initialization phase before the operating system fully boots. This early security assessment ensures that resource configuration decisions are made based on accurate network trust information, preventing security issues later while the cost of this preliminary check is amortized over the entire system operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the timing parameter of security checks from post-initialization to during-initialization. By shifting when network identification occurs, the system can establish security context early without significantly impacting user-perceived startup time, as the initialization phase occurs before user interaction begins

Inventive Principle:
Principle #35Parameter changes

4Object-affected harmful factors

If automatic resource configuration based on network identification is implemented, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automatic network identification and resource configuration without requiring manual user input or intervention. The system autonomously determines network trust status and configures appropriate resource states, reducing operational complexity for users while maintaining strong security protection through automated decision-making

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11343230B2Method for configuring device resources based on network identification and system therefor
Publication Date: 2022.05.24 DELL PROD LP
  • US11343230B2 patent drawing
  • US11343230B2 patent drawing
  • US11343230B2 patent drawing

AI summary

A method for configuring resources at an information handling system may include determining, during initialization, a wide area network (WAN) Internet Protocol (IP) address associated with the information handling system, and retrieving a list of trusted IP addresses from a storage location at the information handling system. The method may further include configuring a first resource at the information handling system to operate in a first state in response to determining that the WAN IP address is included at the list of trusted IP addresses, and configuring the first resource at the information handling system to operate in a second state in response to determining that the WAN IP address is not included at the list of trusted IP addresses.