Self-Encrypting Disk Provisioning for Secure Bare-Metal Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods of managing on-premise computing infrastructure face inefficiencies, errors, and security vulnerabilities, particularly in managing self-encrypting disks (SEDs) in offsite deployments, and there is a need for automated and secure management of computing resources.

Innovation Solution

A computer-implemented method and system that includes an orchestrator module, server management module with encryption and decryption functions, key management module, file transfer module, and Intelligent Platform Management Interface module to automate and secure the management of self-encrypting disks, ensuring efficient resource allocation, robust security, and reliable file transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual processes and disparate tools are used to manage on-premise computing infrastructure, then operational flexibility is maintained, but efficiency and security are compromised

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple disparate management tools and processes into a unified automated management system that integrates provisioning, configuration, monitoring, and security management into a single cohesive platform, thereby improving efficiency while managing complexity through consolidation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent replaces manual mechanical processes with automated software-based management systems that use orchestration engines, APIs, and scripted workflows to perform infrastructure management tasks automatically, eliminating human error and improving productivity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional management methods are used for self-encrypting disks in offsite deployments, then ease of operation is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improvedata securityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the automated management system automatically handles encryption key management, disk provisioning, and security configuration without requiring manual intervention, thereby maintaining high security standards while preserving operational simplicity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary automated management system that acts as a mediator between administrators and self-encrypting disks, handling complex security operations through centralized key management and automated workflows, thus simplifying operations while ensuring robust security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated management systems are implemented, then productivity and security are improved, but device complexity increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidsoftware component complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated management system into distinct modular components including provisioning modules, configuration modules, monitoring modules, and security modules, each handling specific tasks independently. This modular architecture improves productivity through specialized automation while managing complexity by dividing the system into manageable, independently deployable units

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250337571A1Method and system for managing a computing infrastructure
Publication Date: 2025.10.30 OVH
  • US20250337571A1 patent drawing
  • US20250337571A1 patent drawing
  • US20250337571A1 patent drawing

AI summary

A computer-implemented method for managing a computing infrastructure with at least one self-encrypting disk connected to a customer network, involves accessing instructions that orchestrate compute resources and include modules for server management, key management, file transfer, and IPMI. The server management module receives requests from the orchestrator to start nodes and reconfigure hosts, boots hosts over provisioning networks, downloads images, and unlocks self-encrypting disks using passwords stored in the key management system. The method also includes soft rebooting hosts and removing their configuration to switch them back to customer networks.