Remote Management of Non-Standard IHS Devices via Validated Plugins
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current remote management interfaces for Information Handling Systems (IHSs) do not support non-standard hardware devices, leading to security vulnerabilities and inefficiencies in managing customized components within data centers.
Innovation Solution
The implementation of a remote management system that includes a remote access controller and plugins to manage non-standard devices, using a standardized interface like Redfish, with secure initialization and validation of management software, and isolation of core management processes to prevent exposure to security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If standard remote management interfaces (e.g., Redfish) are used to manage hardware components, then remote management capability is enabled, but non-standard devices cannot be managed
Solution Approach 1:
The system segments remote management functionality into standard interface components and non-standard device components. Standard devices are managed through established protocols like Redfish, while non-standard devices are managed through separate plugin modules that can be independently developed and validated, allowing each segment to be optimized for its specific requirements without compromising the other
Solution Approach 2:
The patent introduces plugin modules as intermediary components between the standard remote management interface and non-standard devices. These plugins act as translators that convert standard management commands into device-specific operations, enabling compatibility without requiring changes to the core standardized interface or the non-standard devices themselves
2Adaptability or versatility
If non-standard devices are managed through custom interfaces, then device-specific functionality is achieved, but security vulnerabilities increase
Solution Approach 1:
The system performs preliminary validation of plugin modules during the boot process before they are activated for device management. Checksum verification and digital signature validation are conducted in advance to ensure plugin integrity and authenticity, preventing malicious or corrupted plugins from compromising system security
Solution Approach 2:
The plugin architecture introduces an intermediary layer that isolates non-standard device management from the core standardized management interface. This intermediary layer enforces security policies, validates plugin authenticity, and controls communication between standard and non-standard components, containing potential security risks within the plugin boundary
3Ease of operation
If management software is loaded during operation, then flexibility is improved, but system integrity may be compromised
Solution Approach 1:
The system performs preliminary validation of management software during the boot process, before the software is executed. Checksum verification and digital signature validation are conducted on all plugin modules during system initialization, ensuring that only authenticated and unmodified software is loaded into memory and activated for device management
Solution Approach 2:
The patent replaces traditional mechanical or manual software loading mechanisms with automated digital validation systems. Digital signatures and cryptographic checksums substitute for physical media verification, enabling automatic integrity checking of management software during the boot process without requiring manual intervention or physical media
Data Source
AI summary
Support is provided for remote monitoring and management of non-standard devices of an IHS (Information Handling System) that are not supported by a remote management interface, such as the Redfish management interface. The IHS may be configured for remote management of a non-standard device as part of the manufacture of the IHS. Software for management of the non-standard device is validated against a checksum stored to the IHS during its manufacture to confirm the software for managing the non-standard device has not been altered. If the software is validated, the software is used to initialize a plugin for management of the non-standard device. Data collected by the plugin from monitoring of the non-standard device is provided to a remote access controller of the IHS and the remote access controller issues commands to the non-standard device via the plugin.


