Network Slice Certificate Provisioning for Endpoint Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high cost and complexity of securing Out-Of-Band (OOB) connections in information handling systems, particularly due to conventional certificate provisioning methods that require additional hardware and software, make it inefficient for deploying multiple client computing devices.

Innovation Solution

An Information Handling System (IHS) with a network slice certificate provisioning and management engine that establishes connections with multiple network slices via a Radio Access Network (RAN) system to provision certificates and enable secure communications, optimizing networking connectivity for each application or workload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional certificate provisioning methods are used (USB device or second secure network adapter), then secure OOB connection is achieved, but device complexity and provisioning cost increase

Engineering Contradiction:
Improvesecure OOB connectionVSAvoidhardware and software requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The primary network adapter device is made multi-functional by enabling it to perform both In-Band networking operations and Out-Of-Band networking operations. This eliminates the need for a dedicated second secure network adapter, reducing hardware complexity while maintaining secure OOB connection capabilities through certificate provisioning over the same physical interface

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A certificate provisioning server acts as an intermediary to securely provision certificates to client computing devices over the In-Band connection. This mediator enables secure OOB communication without requiring complex local software on the client device, centralizing the security management function

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional certificate provisioning methods are used (USB device or second secure network adapter), then secure OOB connection is achieved, but provisioning time and cost increase

Engineering Contradiction:
Improvesecure OOB connectionVSAvoidcertificate provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Certificates are pre-configured on a centralized certificate provisioning server, allowing for automated distribution to multiple client computing devices. This preliminary preparation enables rapid provisioning without manual USB device installation for each device, significantly reducing deployment time when deploying multiple devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service certificate provisioning where the client computing device can automatically receive and install certificates through the In-Band connection without requiring manual intervention or additional hardware. This automated process eliminates the time-consuming manual USB device insertion and certificate installation steps

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11012858B1Endpoint computing device network slice secure certificate provisioning and management system
Publication Date: 2021.05.18 DELL PROD LP
  • US11012858B1 patent drawing
  • US11012858B1 patent drawing
  • US11012858B1 patent drawing

AI summary

An endpoint computing device network slice certificate provisioning and management system includes a core network system that is coupled to a Radio Access Network (RAN) system and configured to allocate a plurality of a network slices and make each of the network slices available for use in wireless communications via the RAN system. An endpoint computing device is configured to establish a first network connection with a first network slice included in the plurality of network slices and perform, via certificate provisioning wireless communications over the first network connection with the first network slice, certificate provisioning operations to provision a certificate for the endpoint computing device. The endpoint computing device may then use the certificate to verify at least one server device to provide at least one verified server device, and perform secure network communications with the at least one verified server device.