Self-Encrypting Drive Setup Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current self-encrypting drive (SED) setup processes for Information Handling Systems (IHS) are complex and error-prone, requiring manual registration with an External Key Management Server (EKMS), which can be cumbersome and inefficient, especially in large, diversified computing environments.

Innovation Solution

A self-encrypted drive setup system that uses a systems manager to store user account information associated with an EKMS, generating a Certificate Signing Request (CSR) and obtaining a signed EKMS certificate to securely configure the SED, simplifying the registration process and enabling simultaneous setup of multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual registration process with EKMS is used, then security key management is achieved, but setup complexity and error rate increase

Engineering Contradiction:
Improvesecurity key managementVSAvoidsetup process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-registration with EKMS automatically without requiring manual user intervention. The SED retrieves stored account information, generates CSR, obtains certificates, and completes registration autonomously, eliminating manual setup steps while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

User account information is pre-stored in the SED during manufacturing or provisioning. This preliminary action enables the device to automatically perform registration and certificate acquisition without requiring manual setup later, reducing complexity while ensuring security is established in advance.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual registration process is used, then individual device setup is possible, but time consumption and inefficiency increase

Engineering Contradiction:
Improveindividual device setupVSAvoidsetup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

Each SED autonomously completes its own registration with EKMS by retrieving pre-stored account information, generating its own CSR, and obtaining its own certificates. This self-service capability eliminates the need for manual operator intervention, dramatically reducing setup time while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Account information is pre-configured in each device before deployment. This preliminary action allows devices to immediately perform automatic registration upon activation, eliminating time-consuming manual setup steps while keeping the operation simple for end users.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated registration is implemented, then setup efficiency increases, but system complexity increases

Engineering Contradiction:
Improvesetup efficiencyVSAvoidregistration system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The SED automatically performs all registration tasks including retrieving pre-stored account information, generating CSR, communicating with EKMS, and installing certificates. This automation dramatically improves setup efficiency while the complexity is confined to the background automated processes rather than user-facing operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230105250A1Self-encrypting device (SED) setup system and method
Publication Date: 2023.04.06 DELL PROD LP
  • US20230105250A1 patent drawing
  • US20230105250A1 patent drawing
  • US20230105250A1 patent drawing

AI summary

A self-encrypted drive (SED) setup system uses a systems manager executable program that stores user account information associated with an External Key Management Server (EKMS) service provided by an EKMS in which the user account information has a unique identifier of an associated Information Handling System (IHS). Using the stored user account information, the systems manager may setup a secure encrypted drive (SED) on the IHS by generating a Certificate Signing Request (CSR) for the IHS, communicate with a Certificate Authority (CA) associated with the EKMS to obtain a signed CSR and an EKMS certificate, and load the signed CSR and the EKMS certificate on the IHS when the IHS is to be registered for use with the EKMS. The EKMS service is configured to provide a key for the computing device.