Network Interface Card Automated Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in maintaining remote site security for local area networks, requiring constant updates and manual intervention to ensure security policies are enforced across devices.

Innovation Solution

A network interface card with embedded capabilities for automated network discovery, port configuration, and secure connection establishment with a cloud service broker, enabling zero-touch provisioning and continuous security policy application across devices in a protected network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates and intervention are used to enforce security policies, then security can be maintained, but the complexity of operation and time consumption increase significantly

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidmanual intervention required
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network interface card is equipped with an embedded processor that enables it to autonomously perform network discovery, device identification, and security policy application without requiring manual configuration or intervention. The system self-provisions by automatically contacting the cloud service broker, receiving security policies, and enforcing them locally, thereby eliminating the need for manual updates while maintaining reliable security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies are pre-configured and stored in the cloud service broker before deployment. When the network interface card connects to the network, it automatically retrieves and applies these pre-prepared security policies, eliminating the need for manual updates and ensuring that security measures are in place before any potential security incidents occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual updates are performed to ensure security policies are enforced, then security reliability improves, but the time and resources required increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes continuous automated communication between the network interface card and the cloud service broker. Security policies are continuously updated and enforced in real-time as the card connects to the network, eliminating the downtime and delays associated with manual update schedules. This continuous automated process ensures up-to-date security enforcement without time loss.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The network interface card autonomously performs network discovery, identifies connected devices, retrieves appropriate security policies from the cloud service broker, and applies them automatically. This self-service capability eliminates the time required for manual intervention in security policy updates, ensuring immediate and consistent enforcement across all devices.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automated network discovery and configuration are implemented, then ease of operation improves, but device complexity increases

Engineering Contradiction:
Improveautomated configurationVSAvoidnetwork interface card capabilities
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network interface card integrates multiple functions including network connectivity, embedded processing capabilities, network discovery protocols, device identification, and security policy enforcement into a single universal component. This multi-functionality enables automated configuration and discovery without requiring separate dedicated devices, thereby improving ease of operation while managing device complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cloud service broker acts as an intermediary between the network interface card and the security policy management system. The card communicates with the broker to automatically provision and receive security policies, which simplifies the overall system architecture and reduces the complexity burden on the card itself by offloading policy management to the broker.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11258624B2System and method for providing remote site security for information handling systems in a protected network
Publication Date: 2022.02.22 DELL PROD LP
  • US11258624B2 patent drawing
  • US11258624B2 patent drawing
  • US11258624B2 patent drawing

AI summary

A network interface card includes a memory configured to store a credential associated with one of a manufacturer of the network interface card, a particular manufacturer of the server that includes the network interface card, or another manufacturer of an enclosure that holds the network interface card. A processor performs network discovery to identify devices in a local area network, performs port configuration, and establishes a secure network connection with a cloud service broker. Subsequent to the establishment of the secure network connection, the processor submits a provisioning request to the cloud service broker, receives a response to the provisioning request, and applies the security policies to the network interface card, wherein the security policies are for the devices of the local area network.