OS Image Deployment via Isolated Network Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing OS image deployment in data centers is insecure due to the use of multi-drop networks, where each deployed OS image is accessible by all devices connected to the network, compromising security.

Innovation Solution

A one-to-one secure network connection is established using an OS imaging service container, which is generated in response to a request for provisioning a server with a selected OS image, allowing secure transmission and deletion after provisioning, ensuring isolated and secure OS image deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a multi-drop network is used for OS image deployment, then network resource sharing and ease of deployment are improved, but security is compromised because each deployed OS image is accessible by all devices connected to the network

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network deployment process by creating isolated network connections for each server provisioning operation. Instead of using a shared multi-drop network where all devices can access all OS images, the system establishes dedicated point-to-point connections that segment network access so that each server can only access its assigned OS image through its own isolated connection channel.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a multi-drop network is used for OS image deployment, then device complexity is reduced, but security is compromised due to unauthorized access risks

Engineering Contradiction:
Improvenetwork infrastructure complexityVSAvoidunauthorized access
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary provisioning server that mediates between the OS image storage and the target servers. This intermediary establishes temporary, isolated network connections to transfer OS images securely. The intermediary acts as a controlled gateway that prevents direct access between arbitrary network devices, thereby blocking unauthorized access while maintaining manageable device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If isolated one-to-one network connections are established for each server provisioning, then security is improved, but device complexity and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork connection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic network connection management where isolated point-to-point connections are automatically created, used, and torn down based on provisioning needs. The system dynamically establishes secure connections only when needed for specific server provisioning operations and automatically terminates them afterward. This dynamic approach maintains high security through isolation while avoiding the complexity of permanently managing multiple isolated connections.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs temporary network connections that are discarded after use. Each provisioning operation creates a dedicated isolated connection, uses it to transfer the OS image securely, then discards the connection. This approach recovers network resources by eliminating the need to maintain multiple permanent isolated connections, thereby reducing overall system complexity while preserving the security benefits of isolation during active provisioning.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11748113B2Operating system installation mechanism
Publication Date: 2023.09.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11748113B2 patent drawing
  • US11748113B2 patent drawing
  • US11748113B2 patent drawing

AI summary

A system to facilitate operating system (OS) installation is described. The system includes a server and rack controller, including one or more processors to generate an imaging service comprising an OS image container, transmit data via a first network to initiate a boot up process at a server and download an OS image included in the OS image container via a second network, wherein the second network is separate from the first network.