Secure Server Boot via Integrated Management Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for booting up servers in a datacenter, such as manual IP address assignment and DHCP/PXE, are either time-consuming or pose security concerns, necessitating a more efficient and secure approach for acquiring network addresses during the boot process.

Innovation Solution

A method where an integrated management module (IMM) intercepts the network boot option initiated by a server and acquires a network address for the server via a local connection without using a DHCP server, allowing the server to boot using a network boot option while avoiding security risks associated with DHCP and PXE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DHCP and PXE are used to boot servers, then the boot process is automated and faster, but security risks increase due to potential vulnerabilities in these protocols

Engineering Contradiction:
Improveboot speedVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary device (such as a network switch or dedicated security appliance) that sits between the PXE/DHCP infrastructure and the server. This intermediary intercepts PXE boot requests and DHCP traffic, validates them against security policies, and either allows or blocks them accordingly. This enables organizations to maintain automated network boot capabilities while adding a security layer that prevents malicious exploitation of PXE and DHCP vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If manual IP address assignment is used, then security control is improved, but the boot process becomes time-consuming

Engineering Contradiction:
Improvesecurity controlVSAvoidboot time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring IP address pools, reservation mappings, and security policies in the intermediary device before boot operations begin. The system pre-allocates IP addresses to specific servers based on their hardware identifiers (MAC addresses, serial numbers) and pre-establishes security rules. When a server needs to boot, the intermediary device can quickly assign a pre-approved IP address without requiring real-time manual intervention, thus maintaining both security control and fast boot times.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If DHCP servers are deployed in the network, then automated IP distribution is achieved, but the system complexity increases

Engineering Contradiction:
Improveautomated IP distributionVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the intermediary device universal by enabling it to perform multiple functions: it acts as a DHCP relay agent, a PXE boot authorization server, an IP address manager, and a security policy enforcement point all in one device. This eliminates the need for separate DHCP servers and security appliances, reducing overall system complexity while maintaining automated IP distribution capabilities. The intermediary device integrates these functions into a single coordinated system that manages the entire boot process securely.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10346178B2Secure network server boot without the use of DHCP and PXE
Publication Date: 2019.07.09 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US10346178B2 patent drawing
  • US10346178B2 patent drawing
  • US10346178B2 patent drawing

AI summary

In one embodiment, a method includes detecting that a processor is attempting to boot a server using a network boot option over a first network. The method also includes receiving a network address, using the processor, from an integrated management module (IMM) connected to the processor via a local connection without using a dynamic host configuration protocol (DHCP) server on the first network. In another embodiment, a computer program product includes a computer readable program medium. The computer readable program medium includes program instructions configured to cause a processor in an IMM to intercept a network boot option initiated by a server over a first network and acquire a network address for the server without using a DHCP in the first network. The IMM is connected to the server via a local connection. Other methods, systems, and computer program products are described according to more embodiments.