Secured Network Management Domain Access via Multi-Channel Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Multi-Chassis Management (MCM) group configuration systems lack means to secure communications between the system management domain and network management domain, particularly for synchronized network management domains across modular computing systems, leading to potential unauthorized access.

Innovation Solution

An Information Handling System (IHS) with a processing system and memory that includes instructions to provide a management module with an enclosure controller and management service, which retrieves and validates master I/O module secured access information via secure communication channels to ensure secure access to the network management domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional MCM group configuration systems are used to manage modular computing systems, then system management functionality is provided, but secure access to the network management domain is not implemented

Engineering Contradiction:
Improvesecure accessVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing secure communication channels and retrieving secured access information before any management operations are executed. The enclosure controller obtains credentials from the master I/O module in advance, and the management service validates these credentials before accessing the network management domain, preventing unauthorized access proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management service acts as an intermediary between the enclosure controller and the network management domain. It retrieves secured access information from the enclosure controller, validates it against the master I/O module, and only then permits access to the network management domain. This intermediary layer ensures that no direct unauthorized access can occur.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple network management domains are provided for each modular computing system, then each system has independent management capability, but access security across the group is compromised

Engineering Contradiction:
Improveindependent management capabilityVSAvoidgroup-wide access security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the network management domains of multiple modular computing systems into a single unified network management domain for the entire MCM group. Instead of maintaining separate network management domains for each system, the master I/O module provides a shared network management domain that all systems access through secure channels, ensuring consistent security policies across the group while preserving individual system management capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If secured access information is retrieved and validated through multiple communication channels, then access security is enhanced, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidcommunication channel structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the access control process into distinct functional components operating on separate communication channels: the enclosure controller retrieves secured access information via a first communication channel from the master I/O module, the management service receives this information via a second communication channel, and validation occurs through a third communication channel. This segmentation allows each channel to be optimized for its specific function while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11424997B2Secured network management domain access system
Publication Date: 2022.08.23 DELL PROD LP
  • US11424997B2 patent drawing
  • US11424997B2 patent drawing
  • US11424997B2 patent drawing

AI summary

A secured network management domain access system includes a chassis housing a master I/O module that is configured to provide a network management domain, and a management module coupled to the master I/O module. The management module includes an enclosure controller coupled to the master I/O module via a first communication channel, and that retrieves master I/O module secured access information from the master I/O module via the first communication channel. The management module also includes a management service coupled to the enclosure controller via a second communication channel and to the master I/O module via a third communication channel, and that retrieves the master I/O module secured access information from the enclosure controller via the second communication channel, and performs validation operations with the master I/O module via the third communication channel such that the management service may securely access the network management domain via the master I/O module.