Secured Network Management Domain Access via Multi-Channel Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Multi-Chassis Management (MCM) group configuration systems lack means to secure communications between the system management domain and network management domain, particularly for synchronized network management domains across modular computing systems, leading to potential unauthorized access.
Innovation Solution
An Information Handling System (IHS) with a processing system and memory that includes instructions to provide a management module with an enclosure controller and management service, which retrieves and validates master I/O module secured access information via secure communication channels to ensure secure access to the network management domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional MCM group configuration systems are used to manage modular computing systems, then system management functionality is provided, but secure access to the network management domain is not implemented
Solution Approach 1:
The system performs preliminary actions by establishing secure communication channels and retrieving secured access information before any management operations are executed. The enclosure controller obtains credentials from the master I/O module in advance, and the management service validates these credentials before accessing the network management domain, preventing unauthorized access proactively rather than reactively.
Solution Approach 2:
The management service acts as an intermediary between the enclosure controller and the network management domain. It retrieves secured access information from the enclosure controller, validates it against the master I/O module, and only then permits access to the network management domain. This intermediary layer ensures that no direct unauthorized access can occur.
2Adaptability or versatility
If multiple network management domains are provided for each modular computing system, then each system has independent management capability, but access security across the group is compromised
Solution Approach 1:
The patent merges the network management domains of multiple modular computing systems into a single unified network management domain for the entire MCM group. Instead of maintaining separate network management domains for each system, the master I/O module provides a shared network management domain that all systems access through secure channels, ensuring consistent security policies across the group while preserving individual system management capabilities.
3Reliability
If secured access information is retrieved and validated through multiple communication channels, then access security is enhanced, but system complexity increases
Solution Approach 1:
The system segments the access control process into distinct functional components operating on separate communication channels: the enclosure controller retrieves secured access information via a first communication channel from the master I/O module, the management service receives this information via a second communication channel, and validation occurs through a third communication channel. This segmentation allows each channel to be optimized for its specific function while maintaining overall system security.
Data Source
AI summary
A secured network management domain access system includes a chassis housing a master I/O module that is configured to provide a network management domain, and a management module coupled to the master I/O module. The management module includes an enclosure controller coupled to the master I/O module via a first communication channel, and that retrieves master I/O module secured access information from the master I/O module via the first communication channel. The management module also includes a management service coupled to the enclosure controller via a second communication channel and to the master I/O module via a third communication channel, and that retrieves the master I/O module secured access information from the enclosure controller via the second communication channel, and performs validation operations with the master I/O module via the third communication channel such that the management service may securely access the network management domain via the master I/O module.


