Unified Server Authentication via Service Processor Credential Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current server management systems require multiple authentication credentials for users to access both service processors and management agents, leading to administrative complexity and security risks due to the need for credential synchronization across different systems.

Innovation Solution

A unified authentication mechanism where users provide credentials to either a service processor for out-of-band management or a management agent for in-band management, with the system authenticating these credentials using an operating system interface, allowing for single credential management across both paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication credentials are maintained for service processor and management agent, then each system can independently authenticate users, but the number of credentials increases and administrative complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication mechanisms of the service processor and management agent by having the service processor forward received credentials to the management agent for authentication. This combines two separate authentication paths into a unified flow where a single credential set can authenticate against both systems, reducing credential management complexity while maintaining authentication reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the credential set universal by enabling it to serve dual purposes: authenticating users to the service processor directly and simultaneously authenticating users to the management agent through the service processor's forwarding mechanism. This multi-functionality eliminates the need for separate credential sets for different management paths.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication credentials are required for different management paths, then each path can be securely authenticated, but user management becomes more difficult and security risks increase

Engineering Contradiction:
Improveauthentication securityVSAvoiduser management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines the authentication security requirements of both management paths by implementing a unified authentication flow. The service processor receives credentials and forwards them to the management agent, ensuring that a single credential set undergoes authentication checks for both systems, thereby maintaining security while simplifying user management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The service processor acts as an intermediary in the authentication process. It receives credentials from the user, forwards them to the management agent for verification, and relays the authentication result. This intermediary role allows a single credential set to be validated against both authentication systems without requiring the user to manage multiple credentials, thus improving ease of operation while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If centralized authentication mechanism like LDAP is implemented, then credential synchronization is improved, but additional infrastructure resources and implementation complexity increase

Engineering Contradiction:
Improvecredential synchronizationVSAvoidinfrastructure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a self-service authentication approach where the service processor itself handles the credential forwarding and authentication coordination with the management agent. Rather than requiring external centralized infrastructure like LDAP, the service processor uses its existing communication capabilities to autonomously manage the authentication flow, reducing infrastructure complexity while maintaining credential synchronization.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8347378B2Authentication for computer system management
Publication Date: 2013.01.01 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US8347378B2 patent drawing
  • US8347378B2 patent drawing
  • US8347378B2 patent drawing

AI summary

An improved solution for authenticating a user seeking to manage a computer system is provided according to aspects of the invention. A user seeking to perform out-of-band management of the computer system can provide a set of credentials to a service processor, which in turn provides them to the computer system for authentication. Additionally, a user seeking to perform in-band management of the computer system can provide a set of credentials to a management agent executing on the computer system for authentication. In either case, the computer system can authenticate the set of credentials, e.g., using an operating system interface.