Proxied Virtual Wireless Endpoints for Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems in data centers face challenges in efficiently managing and securing wireless connections for out-of-band management and control, particularly in ensuring secure access and authorization for mobile devices, while maintaining physical proximity and preventing unauthorized remote attacks.

Innovation Solution

The implementation of a system and method for providing proxied virtual wireless end points in a server rack, utilizing wireless management modules with features like activation switches, authentication schemes, and proximity-based security, along with management controllers and transceiver modules for secure WiFi and Bluetooth connectivity, enables secure and authorized access while ensuring physical proximity and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless connections are opened for management access, then ease of operation is improved, but security is worsened due to potential unauthorized remote attacks

Engineering Contradiction:
Improvemanagement accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A proxied virtual wireless endpoint is introduced as an intermediary between the management network and wireless clients. This proxy endpoint receives and forwards management traffic, acting as a secure gateway that prevents direct access to the management network while still enabling operational access through controlled channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments wireless access into different virtual endpoints: dedicated management endpoints for out-of-band management traffic and proxied virtual endpoints for data plane traffic. This segmentation isolates management functions from data traffic, allowing management access while preventing unauthorized remote attacks on the core management network.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical proximity requirements are enforced, then security is improved, but ease of operation is worsened due to restricted access

Engineering Contradiction:
ImprovesecurityVSAvoidaccess
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system transitions from enforcing physical proximity in three-dimensional space to verifying proximity through virtual network dimensions. Instead of requiring physical presence near the server rack, the proxied virtual endpoint creates a virtual access point that maintains security through network-layer proximity verification while allowing operational flexibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If multiple wireless endpoints are provided for different functions, then adaptability is improved, but device complexity is worsened

Engineering Contradiction:
Improvewireless access functionalityVSAvoidendpoint management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The proxied virtual wireless endpoint is designed with multi-functionality, serving both as a management access point and a data plane access point. This universal endpoint can handle different types of wireless traffic (management and data) through a single unified interface, reducing the need for multiple separate endpoints and simplifying overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9929901B2System and method for providing proxied virtual wireless end points in a server rack of a data center
Publication Date: 2018.03.27 DELL PROD LP
  • US9929901B2 patent drawing
  • US9929901B2 patent drawing
  • US9929901B2 patent drawing

AI summary

A server blade chassis, includes a server blade and a management system. The server blade includes a host processor and a blade management controller. The host processor provides a hosted environment and the blade management controller provides a managed environment separate from the hosted environment. The managed environment includes a virtual wireless device. The management system including a wireless management module and a chassis management controller. The wireless management module couples a wireless device to the management system and the chassis management controller provides a management request from the wireless device to the virtual wireless device.