Remote Access Controller IHS Discovery via DNS Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing large groups of Information Handling Systems (IHSs) in data centers are inefficient and error-prone, particularly when new or reconfigured IHSs are added, as they require manual credentialing and exhaustive network scanning, which is time-consuming and prone to errors.
Innovation Solution
A method and system that enables secure discovery of IHSs by remote management tools without login credentials, utilizing a remote access controller to register with a DNS, notify the management tool, and configure the IHS for remote management, with a secure memory storing a trusted security certificate for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual credentialing and exhaustive network scanning are used to discover new IHSs, then the remote management tool can identify new devices, but the process becomes time-consuming and error-prone
Solution Approach 1:
Instead of the remote management tool actively scanning the network to discover IHSs, the invention inverts the approach by having IHSs actively notify the remote management tool of their presence. The remote access controller on each IHS monitors for initialization events and sends notifications to the management tool, reversing the traditional client-server discovery model and eliminating the need for exhaustive network scanning.
Solution Approach 2:
The remote access controller on each IHS is pre-configured with a security certificate during manufacturing or initial setup. This preliminary action ensures that when the IHS needs to notify the remote management tool, authentication credentials are already in place, eliminating the need for manual credentialing during the discovery process and enabling immediate secure communication.
2Reliability
If login credentials are required for IHS discovery, then security is maintained, but manual credentialing increases complexity and errors
Solution Approach 1:
Each IHS is equipped with a self-contained security certificate that enables it to autonomously authenticate itself to the remote management tool without requiring external credential provisioning. The remote access controller uses this pre-configured certificate to sign notifications, allowing the IHS to serve its own authentication needs and eliminating manual credential management for administrators.
Solution Approach 2:
The security certificate acts as an intermediary authentication mechanism between the IHS and the remote management tool. Rather than requiring direct credential exchange or manual authentication, the signed notification serves as a trusted intermediary that proves the IHS's identity, simplifying the authentication process while maintaining security through cryptographic verification.
3Productivity
If exhaustive network scanning is performed to find new IHSs, then all devices can be detected, but the process is time-consuming and resource-intensive
Solution Approach 1:
The system implements a feedback mechanism where the remote access controller on each IHS continuously monitors for initialization events and immediately notifies the remote management tool when a new device comes online. This event-driven feedback loop ensures that the management tool receives real-time updates about new IHSs without needing to continuously scan the network, dramatically reducing resource consumption while maintaining high discovery speed.
Data Source
AI summary
Embodiments provide secure discovery of a first IHS operating within a plurality of IHSs (Information Handling Systems), such as within a data center, by a remote management tool. The remote management tool is registered with a DNS (Domain Name System). Upon initializing a first IHS, that first IHS is not automatically recognized by the remote management tool. A remote access controller of the first IHS retrieves information from the registration of the remote management tool from the DNS. The remote access controller notifies the remote management tool of the initialized first IHS. The notification is transmitted, by the remote access controller, to a network address specified in the DNS registration information of the remote management tool. The remote management tool confirms the authenticity of the notification provided by the remote access controller and configures the first IHS for remote management.


