Secure Bare Metal Provisioning via Removable Kernel Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face security vulnerabilities when third parties add imposter devices, as existing methods automatically push confidential programs and configuration information, leading to manual installation and configuration requirements that are time-consuming and hinder dynamic expansion and scalability.

Innovation Solution

A method for discovering and provisioning computing devices in a security-enhanced environment involves adding bare metal devices with removable media containing a first kernel, which runs a discovery module to gather device information and a network module to access a provisioning system, allowing selective installation of an operating system without exposing the device to proprietary information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automatic discovery protocols are used to provision computing devices, then device provisioning efficiency is improved, but security vulnerabilities increase due to automatic pushing of confidential programs and configuration information

Engineering Contradiction:
Improvedevice provisioning efficiencyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a removable media device as an intermediary between the bare metal machine and the network provisioning system. This intermediary stores a first kernel that enables device discovery and provisioning without directly exposing the machine to proprietary information on the network, thus resolving the security vulnerability while maintaining provisioning efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the provisioning process into distinct phases: a first kernel loaded from removable media handles device discovery and communication, while a second kernel (OS installer) is subsequently loaded. This segmentation allows secure device identification without automatically pushing confidential programs, addressing both security and efficiency concerns

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual installation and configuration of computer programs is required, then security control is improved, but time consumption increases and scalability is reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The bare metal machine performs self-discovery by loading the first kernel from removable media, which automatically gathers device information and communicates with the provisioning system. This self-service mechanism eliminates the need for manual installation while maintaining security control through the intermediary removable media, reducing time consumption without sacrificing security

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If removable media with first kernel is used for device discovery, then security vulnerability is reduced, but device complexity increases

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses removable media as a disposable intermediary that contains the first kernel. This simple, easily replaceable medium provides the necessary security functionality without adding permanent complexity to the device architecture. The removable media can be easily inserted and removed, making the security mechanism simple to implement and maintain

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11233813B2Discovering and provisioning computing devices in a security enhanced environment
Publication Date: 2022.01.25 RED HAT ISRAEL
  • US11233813B2 patent drawing
  • US11233813B2 patent drawing
  • US11233813B2 patent drawing

AI summary

Systems and methods for discovering and provisioning computing devices within a computing environment. An example method may comprise: loading a first kernel from a removable storage, wherein the first kernel identifies device information of the computing device when executed; transmitting a provisioning request comprising the device information to a provisioning device over a network; receiving provisioning data and a second kernel over a network, the second kernel comprising an operating system installer; and overwriting the first kernel with the second kernel.