PCI Express Security Configuration Capability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems lack a centralized method to manage and report security characteristics across multiple security platforms, making it difficult for devices to operate securely and efficiently.

Innovation Solution

A system and method that utilizes the PCI Express communications protocol to identify and manage security parameters through a capabilities data structure, allowing processors to access and control security features across different security protocols without modifying existing standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple security protocols are used across devices, then security coverage and versatility are improved, but system complexity and difficulty of centralized management increase

Engineering Contradiction:
Improvesecurity protocol compatibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration capability within the PCI Express protocol that acts as an intermediary layer between devices with different security protocols and the central processor. This capability includes a data structure that standardizes security parameter reporting, allowing the processor to manage multiple security protocols through a unified interface without direct complexity from each protocol implementation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The PCI Express configuration capability is designed as a universal mechanism that can handle multiple security protocols through a single standardized interface. The capability data structure is multi-functional, capable of reporting security characteristics across different security platforms while maintaining a consistent communication framework

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If devices operate independently under different security protocols, then device autonomy and security specialization are improved, but centralized provisioning and initialization capability deteriorate

Engineering Contradiction:
Improvesecurity protocol diversityVSAvoidcentralized provisioning capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The configuration capability implements a feedback mechanism where devices report their security characteristics and parameters back to the processor through the standardized PCI Express data structure. This feedback loop enables the processor to understand the security state of each device and perform centralized provisioning and initialization appropriate to each device's specific security protocol requirements

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The standardized configuration capability serves as an intermediary that translates between device-specific security protocol parameters and the universal PCI Express communication framework, enabling centralized management while preserving device autonomy and protocol diversity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If security parameters are not reported by devices, then device simplicity is maintained, but processor control over security features is reduced

Engineering Contradiction:
Improvedevice configuration overheadVSAvoidprocessor security control
Core Design Contradiction:
Device complexityVSExtent of automation

Solution Approach 1:

The device automatically reports its security parameters and characteristics to the processor through the configuration capability without requiring manual configuration or additional complexity in the device. The reporting mechanism is self-activating and integrated into the device's operation, providing the processor with the information needed for security control while maintaining device simplicity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9710418B2System and method for security configuration
Publication Date: 2017.07.18 DELL PROD LP
  • US9710418B2 patent drawing
  • US9710418B2 patent drawing
  • US9710418B2 patent drawing

AI summary

A system and method for accessing and identifying the security parameters of a device in an information handling system is disclosed. A device in a computer system may operate according to a defined security protocol, and multiple security protocols may exist across the devices of the system. In operation, a configuration capability is defined within the PCI Express communications protocol. This capability includes a capabilities data structure through which parameters concerning the security parameters of the device may be identified and passed to a processor.