Remote Management Console Lockout Against Hijacking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote management systems are vulnerable to unauthorized local console hijacking when remote management connections are lost or disconnected, as previous solutions require rebooting or reconfiguring to disable local controls.

Innovation Solution

Implementing management traps, such as keyboard shortcuts or application-based notifications, to lock the local console automatically when a remote management connection is lost, requiring credentials to unlock the operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote management is enabled to reduce downtime and management costs, then productivity and cost efficiency are improved, but server vulnerability to local console hijacking increases

Engineering Contradiction:
Improveremote management efficiencyVSAvoidserver security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies preliminary anti-action by automatically triggering a lockout mechanism when remote management connectivity is lost. The management processor monitors connection status and preemptively secures the local console by locking it out, preventing potential hijacking before unauthorized access can occur. This proactive security measure resolves the contradiction by enabling remote management while automatically preventing local console exploitation.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If local controls are disabled to prevent hijacking, then server security is improved, but system operability and ease of local access deteriorate

Engineering Contradiction:
Improveconsole securityVSAvoidlocal console access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamics by making the local console access state changeable based on remote management connection status. When remote connectivity is established, the local console is locked out for security. When remote connectivity is lost or interrupted, the system dynamically unlocks the local console to restore access. This dynamic state adjustment resolves the contradiction by providing security when needed while maintaining operational accessibility when remote management is unavailable.

Inventive Principle:
Principle #15Dynamics

3Reliability

If previous security measures like disabling local controls are implemented, then hijacking prevention is improved, but system complexity and configuration requirements increase

Engineering Contradiction:
Improveanti-hijacking capabilityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies self-service by implementing automatic monitoring and response mechanisms that require no manual configuration or intervention. The management processor automatically detects remote connection status, triggers lockout actions when connectivity is lost, and manages the security state without user involvement. This automation eliminates complex manual configuration requirements while maintaining robust anti-hijacking capability, resolving the contradiction between security improvement and system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9608884B2System and method for remote management of a computer
Publication Date: 2017.03.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9608884B2 patent drawing
  • US9608884B2 patent drawing
  • US9608884B2 patent drawing

AI summary

There is provided a system and method for remote management of a computer. The method includes establishing a connection between a remote console and a managed server. Additionally, the method includes detecting a change in the status of the connection and issuing commands to lock the managed server if a change in status of the connection is detected.