Rack Server Management via Switch Port Protocol Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for managing rack servers lack efficient and secure methods for establishing communication between management applications and rack servers, particularly in scenarios where user intervention is required for authentication and authorization, and do not support automatic discovery of rack servers.

Innovation Solution

A method and system that utilize predefined protocols like IPMI and DHCP to communicate with management controllers, allowing network traffic under multiple protocols, enabling automatic discovery and secure management of rack servers without user intervention by authenticating and authorizing devices based on predefined parameters and vendor-specific extensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If standardized protocols are used for remote management, then communication compatibility is improved, but security and authentication control are worsened

Engineering Contradiction:
Improvecommunication compatibilityVSAvoidsecurity and authentication control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a management controller as an intermediary device between the rack server and the management application. This controller implements the standardized management interface while performing authentication and authorization functions, thereby maintaining protocol compatibility while enhancing security control through a dedicated intermediary component

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual authentication and authorization are implemented, then security control is improved, but operational efficiency and automation are worsened

Engineering Contradiction:
Improveauthentication and authorization controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication and authorization by the management controller before any management operations occur. The controller pre-establishes security credentials and authorization levels for different users and devices, so that when management applications connect through standardized protocols, authentication is already in place without requiring manual intervention during operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management controller automatically performs authentication and authorization checks without requiring manual user intervention. The system self-services by having the controller independently verify credentials and enforce access policies, eliminating the need for manual security management while maintaining strong authentication controls

Inventive Principle:
Principle #25Self-service

3Reliability

If switch ports are configured to allow only specific protocols, then network security is improved, but device discovery and communication flexibility are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice discovery and communication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by configuring switch ports to allow multiple protocols before device connection occurs. The management application discovers rack servers using DHCP and other protocols, and only after successful discovery and authentication does the system restrict the port to allow only the standardized management protocol, thus enabling initial flexibility while maintaining final security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic protocol configuration on switch ports. Initially, ports are configured to allow multiple protocols for device discovery and communication. After successful authentication and authorization of a rack server, the port configuration dynamically changes to allow only the standardized management protocol, providing both initial flexibility and final security through dynamic adaptation

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8751675B2Rack server management
Publication Date: 2014.06.10 CISCO TECHNOLOGY INC
  • US8751675B2 patent drawing
  • US8751675B2 patent drawing
  • US8751675B2 patent drawing

AI summary

Techniques presented herein provide approaches for managing rack servers. In one embodiment, a message is received from a management controller of a rack server and via a switch port, where the message requests a lease for a network address under a first protocol. Upon determining that the management controller is a supported device, the switch port is configured to allow network traffic under at least a second protocol.