Remote Access Controller IHS Discovery via DNS Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing large groups of Information Handling Systems (IHSs) in data centers are inefficient and error-prone, particularly when new or reconfigured IHSs are added, as they require manual credentialing and exhaustive network scanning, which is time-consuming and prone to errors.

Innovation Solution

A method and system that enables secure discovery of IHSs by remote management tools without login credentials, utilizing a remote access controller to register with a DNS, notify the management tool, and configure the IHS for remote management, with a secure memory storing a trusted security certificate for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual credentialing and exhaustive network scanning are used to discover new IHSs, then the remote management tool can identify new devices, but the process becomes time-consuming and error-prone

Engineering Contradiction:
Improvediscovery accuracyVSAvoiddiscovery time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of the remote management tool actively scanning the network to discover IHSs, the invention inverts the approach by having IHSs actively notify the remote management tool of their presence. The remote access controller on each IHS monitors for initialization events and sends notifications to the management tool, reversing the traditional client-server discovery model and eliminating the need for exhaustive network scanning.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The remote access controller on each IHS is pre-configured with a security certificate during manufacturing or initial setup. This preliminary action ensures that when the IHS needs to notify the remote management tool, authentication credentials are already in place, eliminating the need for manual credentialing during the discovery process and enabling immediate secure communication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If login credentials are required for IHS discovery, then security is maintained, but manual credentialing increases complexity and errors

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each IHS is equipped with a self-contained security certificate that enables it to autonomously authenticate itself to the remote management tool without requiring external credential provisioning. The remote access controller uses this pre-configured certificate to sign notifications, allowing the IHS to serve its own authentication needs and eliminating manual credential management for administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security certificate acts as an intermediary authentication mechanism between the IHS and the remote management tool. Rather than requiring direct credential exchange or manual authentication, the signed notification serves as a trusted intermediary that proves the IHS's identity, simplifying the authentication process while maintaining security through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If exhaustive network scanning is performed to find new IHSs, then all devices can be detected, but the process is time-consuming and resource-intensive

Engineering Contradiction:
Improvediscovery speedVSAvoidscanning resources
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system implements a feedback mechanism where the remote access controller on each IHS continuously monitors for initialization events and immediately notifies the remote management tool when a new device comes online. This event-driven feedback loop ensures that the management tool receives real-time updates about new IHSs without needing to continuously scan the network, dramatically reducing resource consumption while maintaining high discovery speed.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11153300B2Secure node-initiated discovery
Publication Date: 2021.10.19 DELL PROD LP
  • US11153300B2 patent drawing
  • US11153300B2 patent drawing
  • US11153300B2 patent drawing

AI summary

Embodiments provide secure discovery of a first IHS operating within a plurality of IHSs (Information Handling Systems), such as within a data center, by a remote management tool. The remote management tool is registered with a DNS (Domain Name System). Upon initializing a first IHS, that first IHS is not automatically recognized by the remote management tool. A remote access controller of the first IHS retrieves information from the registration of the remote management tool from the DNS. The remote access controller notifies the remote management tool of the initialized first IHS. The notification is transmitted, by the remote access controller, to a network address specified in the DNS registration information of the remote management tool. The remote management tool confirms the authenticity of the notification provided by the remote access controller and configures the first IHS for remote management.