Self-Encrypting Disk Provisioning for Secure Bare-Metal Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods of managing on-premise computing infrastructure face inefficiencies, errors, and security vulnerabilities, particularly in managing self-encrypting disks (SEDs) in offsite deployments, and there is a need for automated and secure management of computing resources.
Innovation Solution
A computer-implemented method and system that includes an orchestrator module, server management module with encryption and decryption functions, key management module, file transfer module, and Intelligent Platform Management Interface module to automate and secure the management of self-encrypting disks, ensuring efficient resource allocation, robust security, and reliable file transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual processes and disparate tools are used to manage on-premise computing infrastructure, then operational flexibility is maintained, but efficiency and security are compromised
Solution Approach 1:
The patent combines multiple disparate management tools and processes into a unified automated management system that integrates provisioning, configuration, monitoring, and security management into a single cohesive platform, thereby improving efficiency while managing complexity through consolidation
Solution Approach 2:
The patent replaces manual mechanical processes with automated software-based management systems that use orchestration engines, APIs, and scripted workflows to perform infrastructure management tasks automatically, eliminating human error and improving productivity
2Reliability
If traditional management methods are used for self-encrypting disks in offsite deployments, then ease of operation is maintained, but security vulnerabilities increase
Solution Approach 1:
The patent implements self-service mechanisms where the automated management system automatically handles encryption key management, disk provisioning, and security configuration without requiring manual intervention, thereby maintaining high security standards while preserving operational simplicity
Solution Approach 2:
The patent introduces an intermediary automated management system that acts as a mediator between administrators and self-encrypting disks, handling complex security operations through centralized key management and automated workflows, thus simplifying operations while ensuring robust security
3Productivity
If automated management systems are implemented, then productivity and security are improved, but device complexity increases
Solution Approach 1:
The patent segments the automated management system into distinct modular components including provisioning modules, configuration modules, monitoring modules, and security modules, each handling specific tasks independently. This modular architecture improves productivity through specialized automation while managing complexity by dividing the system into manageable, independently deployable units
Data Source
AI summary
A computer-implemented method for managing a computing infrastructure with at least one self-encrypting disk connected to a customer network, involves accessing instructions that orchestrate compute resources and include modules for server management, key management, file transfer, and IPMI. The server management module receives requests from the orchestrator to start nodes and reconfigure hosts, boots hosts over provisioning networks, downloads images, and unlocks self-encrypting disks using passwords stored in the key management system. The method also includes soft rebooting hosts and removing their configuration to switch them back to customer networks.


