Remote Management Controller Zero-Touch Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems ship with remote management controllers disabled for security, requiring manual configuration, which prevents secure zero-touch remote provisioning and management.

Innovation Solution

Enabling remote management controllers at manufacture but not provisioning them, embedding authentication data during testing, and providing it to customers for secure remote authentication and provisioning, allowing zero-touch remote management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If remote management controller is enabled at manufacture, then remote provisioning capability is improved, but security risk increases

Engineering Contradiction:
Improveremote provisioning capabilityVSAvoidsecurity risk
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The remote management controller is enabled during manufacture but kept unprovisioned, performing the enabling action in advance while delaying the provisioning action until secure authentication occurs. This preliminary enabling allows the controller to be ready for remote operation without exposing security credentials prematurely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Authentication data acts as an intermediary mechanism that mediates between the enabled controller and the provisioning process. The controller requires this intermediate authentication step before allowing provisioning, creating a secure gateway that prevents unauthorized access while enabling legitimate remote configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If remote management controller is disabled for security, then security risk is reduced, but manual configuration is required

Engineering Contradiction:
Improvesecurity riskVSAvoidmanual configuration requirement
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The controller is preliminarily enabled during manufacture with authentication data embedded, so that when it reaches the customer, it only requires authentication-based provisioning rather than manual configuration. This preliminary setup eliminates the need for physical presence or manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service provisioning where the remote management controller can be configured remotely through automated authentication and provisioning processes. Once enabled with authentication data, the controller serves itself by accepting remote provisioning commands without requiring manual intervention, eliminating the need for技术人员 to physically configure each device.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If authentication data is embedded during testing, then zero-touch provisioning is enabled, but data security handling complexity increases

Engineering Contradiction:
Improvezero-touch provisioningVSAvoiddata security handling
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

Authentication data is extracted from the provisioning process and embedded separately during manufacturing testing. This separation allows the authentication mechanism to be independently secured and managed, simplifying the overall security architecture by isolating sensitive data handling to a specific embedded step rather than distributing security complexity throughout the entire provisioning flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8677459B2Secure zero-touch provisioning of remote management controller
Publication Date: 2014.03.18 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8677459B2 patent drawing
  • US8677459B2 patent drawing
  • US8677459B2 patent drawing

AI summary

Embodiments enable secure zero-touch remote provisioning/management of a computer system. A computer system is shipped to end customers with its remote management controller enabled but not provisioned. During automatic testing, for example, provisioning authentication data is embedded into the remote management controller. The computer system vendor harvests the provisioning authentication data or derivative data therefrom from the remote management controller and stores it in a database. Upon sale of the computer system, the computer system vendor provides to the end-customer the harvested data of the computer system's remote management controller. The end-customer can then remotely authenticate a remote provisioning/management console to the remote management controller. Once successfully authenticated, the remote provisioning/management console can provision the remote management controller with one or more user accounts/roles with corresponding authentication details, authenticate as one of the provisioned user accounts, and perform computer system provisioning using remote manageability functions as desired.