Secure Boot Certificate Namespace Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in managing secure boot certificates, particularly when entities are migrated or re-grouped, leading to difficulties in maintaining certificate synchronization across multiple server computing systems, which can result in configuration issues, malicious attacks, and operating system load failures.

Innovation Solution

A method is introduced where a client computing node provides an interface for a secure boot certificate namespace hierarchy, allowing for the creation and configuration of new namespaces, automatic assignment of certificates, and synchronization of secure boot certificates across server computing systems, ensuring they are always in sync, even when offline, and adapting to new locations or configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure boot certificates are managed locally for each server computing system, then each server can independently validate boot certificates, but managing the set of certificates across thousands of server computing systems becomes difficult and time-consuming

Engineering Contradiction:
Improvecertificate validation reliabilityVSAvoidcertificate management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple certificate management functions into a centralized management system that can remotely manage certificates across multiple server computing systems. The system merges certificate storage, validation, and update operations into a unified remote management architecture, eliminating the need for individual local management of each server's certificates.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a remote management system as an intermediary between administrators and server computing systems. This intermediary handles certificate operations remotely, acting as a mediator that receives management requests and executes them across targeted servers without requiring direct local access to each system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If secure boot certificates are updated remotely, then certificate updates can be deployed across multiple servers, but servers that are offline will have out-of-sync certificates requiring individual configuration

Engineering Contradiction:
Improvecertificate update efficiencyVSAvoidcertificate synchronization
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by providing a mechanism to identify and queue certificate update operations for target server computing systems before execution. The system prepares update requests in advance and maintains a record of which servers require updates, ensuring that when servers come online, they can receive the pending certificate updates automatically.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the remote management system tracks the status of certificate updates across server computing systems. The system receives feedback about which servers have been updated and which remain pending, allowing administrators to monitor synchronization status and retry operations on offline servers when they become available.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If new certificates are introduced or removed from existing systems, then the certificate set can be updated, but unwanted certificates may be left behind which can result in malicious attacks or operating system load failures

Engineering Contradiction:
Improvecertificate set flexibilityVSAvoidsecurity risks from unwanted certificates
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent enables self-service functionality where the remote management system automatically manages the complete certificate lifecycle. The system can identify unwanted or obsolete certificates, remove them from the secure boot certificate store, and ensure that only current, authorized certificates remain. This automated self-service approach eliminates manual certificate management errors and security risks.

Inventive Principle:
Principle #25Self-service

4Manufacturing precision

If secure boot certificates are configured individually for each server computing system, then each system can be precisely configured, but the effort required to selectively configure certificates for thousands of servers becomes a large undertaking

Engineering Contradiction:
Improveconfiguration precisionVSAvoidmanagement system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a remote management system that can perform multiple certificate management operations across different server computing systems through a single unified interface. The system provides universal functionality for creating, updating, removing, and validating certificates across heterogeneous server environments, eliminating the need for separate configuration processes for each server type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11010478B2Method and system for management of secure boot certificates
Publication Date: 2021.05.18 DELL PROD LP
  • US11010478B2 patent drawing
  • US11010478B2 patent drawing
  • US11010478B2 patent drawing

AI summary

Methods, systems, and computer programs encoded on computer storage medium, for providing, by a client computing node, an interface identifying a secure boot certificate namespace hierarchy including a plurality of namespaces; in response to providing the interface, receiving, by the client computing node, a request to create a new namespace within the secure boot namespace hierarchy; configuring the new namespace, including adding a certificate that is to be included by the new namespace, the certificate associated with a server computing system; and assigning the new namespace to the server computing system.