Secure Delta Inventory Migration Across Control Planes with Delegated Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack efficient methods for validating and verifying hardware component changes in Information Handling Systems (IHSs) across control planes, particularly in scenarios where components are replaced or added, leading to potential compromises in the integrity of the root of trust.

Innovation Solution

The implementation of a system that uses delegated authority key pairs and delta inventory certificates managed through eventing and cloud infrastructures to ensure real-time validation and verification of hardware changes, ensuring that only genuine components are installed and maintained across control planes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware components are replaced or added in IHSs, then system functionality and adaptability are improved, but the integrity of the root of trust is compromised

Engineering Contradiction:
Improvehardware customizationVSAvoidroot of trust integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by creating delegated authority key pairs and generating delta inventory certificates before hardware changes occur. The control plane pre-establishes cryptographic credentials that will be used to validate future hardware modifications, ensuring that adaptability can be achieved without compromising trust integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary control plane that acts as a mediator between the root of trust and hardware components. The control plane uses delegated authority key pairs to verify hardware inventory changes without requiring direct access to the root of trust, thus maintaining integrity while enabling customization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual validation of hardware changes is performed, then security is maintained, but time consumption and operational complexity increase

Engineering Contradiction:
Improvesecurity validationVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by enabling automated validation of hardware changes through cryptographic verification. The control plane automatically generates delta inventory certificates and verifies hardware modifications using delegated authority key pairs, eliminating the need for manual security validation while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical validation processes with cryptographic automation. Instead of human operators manually verifying hardware changes, the system uses digital signatures and certificate verification mechanisms to automatically validate hardware inventory, significantly reducing time consumption while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic verification of hardware inventory is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improvehardware validation securityVSAvoidcontrol plane architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic verification system into distinct modular components: delegated authority key pairs for authentication, delta inventory certificates for change tracking, and control plane modules for verification. This segmentation allows complex security functionality to be implemented as independent, manageable units that can be deployed and maintained separately.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250247212A1Secure migration of delta inventory across control planes
Publication Date: 2025.07.31 DELL PROD LP
  • US20250247212A1 patent drawing
  • US20250247212A1 patent drawing
  • US20250247212A1 patent drawing

AI summary

A remote validation service may generate a first delegated authority key pair for a first control plane and may generate a second delegated authority key pair for a second control plane. The first control plane, which may be a current owner control plane, may send to the remote validation service a payload including delta change information and that is signed using a public key of the first delegated authority key pair. The first control plane may then send the delta change information in an ownership voucher to the second control plane. The second control plane, which may be a next owner control plane, may then send to the remote validation service an additional payload including delta change information and that is signed using a public key of the second delegated authority key pair. The remote validation service may then validate the delta change information.