Redundant Key Management via Remote Access Controller Broadcasting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-based key management systems in datacenters represent a single point of failure, leading to inaccessible managed devices in case of data loss or unavailability, necessitating a redundant system that is often underutilized and costly.

Innovation Solution

A redundant key management system is implemented using remote access controller devices that encrypt and broadcast device locking keys across a network, allowing them to be stored and retrieved from multiple servers, eliminating the need for a secondary key management system by utilizing a blockchain for secure key storage and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a network-based key management system is used to centrally manage device locking keys, then key management operations can be performed remotely, but the system becomes a single point of failure that can render managed devices inaccessible

Engineering Contradiction:
Improveremote key management capabilityVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the key management functionality from the centralized key management system and distributes it to individual remote access controllers. Each controller maintains its own copy of device locking keys locally, eliminating the single point of failure while preserving remote key management capabilities through the segmented distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by enabling each remote access controller to store and manage device locking keys locally rather than relying on centralized storage. This local key storage capability ensures that individual controllers can independently unlock managed devices even when the centralized key management system is unavailable.

Inventive Principle:
Principle #3Local quality

2Reliability

If a redundant key management system is provided to ensure availability, then device accessibility is improved, but the cost and complexity of the system increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidredundant system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling each remote access controller to independently store encrypted device locking keys locally and autonomously retrieve them when needed. This self-service capability eliminates the need for a separate redundant key management system, as each controller serves its own key management needs without requiring backup infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If device locking keys are encrypted and broadcast to multiple remote access controllers, then redundant key access is achieved, but the risk of key exposure increases

Engineering Contradiction:
Improvekey access redundancyVSAvoidkey exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-encrypting device locking keys with the public keys of respective remote access controllers before broadcasting. This preliminary encryption ensures that only the intended recipient controllers can decrypt and access the keys, minimizing exposure risk while maintaining redundant access capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses asymmetric encryption as an intermediary mechanism to securely transmit device locking keys to multiple remote access controllers. The encryption process acts as a mediator that protects the keys during transmission and storage, ensuring that even though keys are distributed redundantly, they remain secure through cryptographic protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11252138B2Redundant device locking key management system
Publication Date: 2022.02.15 DELL PROD LP
  • US11252138B2 patent drawing
  • US11252138B2 patent drawing
  • US11252138B2 patent drawing

AI summary

A redundant key management system includes a key management system coupled to a plurality of server devices through a network. A first server device includes a managed device coupled to a first remote access controller device that receive a device locking key from the key management system and uses it to lock the managed device. The first remote access controller device then encrypts the device locking key, broadcasts the encrypted device locking key through the network to a second remote access controller device in a second server device, and erases the device locking key. Subsequently, the first remote access controller device transmits a request to retrieve the encrypted device locking key. When the first remote access controller receives the encrypted device locking key from the second remote access controller device, it decrypts the encrypted device locking key and uses the resulting device locking key to unlock the managed device.