Server Service Processor Security via Proximity Digital Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing servers in data centers before connecting them to a network are cumbersome and time-consuming, as they require direct laptop connections to change default account and password settings, leaving servers vulnerable to rogue software exploitation.

Innovation Solution

Establishing a proximity-based communications connection with a server's service processor before network connection, using a digital certificate to enable access only by a system management server, via methods like NFC or Bluetooth LE, ensuring secure configuration without direct network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct laptop connection is used to configure each server one by one, then security can be ensured by changing default account and password settings, but the process becomes cumbersome and time consuming

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring security settings (digital certificates, password policies, account restrictions) on servers before they are connected to the network. This ensures that security measures are in place before the server becomes vulnerable to network-based attacks, while allowing bulk configuration methods to reduce the time required compared to individual laptop connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a management server that acts as a mediator between the administrator and multiple servers. This management server can push security configurations to multiple servers simultaneously, eliminating the need for individual laptop connections to each server while maintaining security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If server is connected to network before securing service processor, then network access is available, but server becomes vulnerable to rogue software exploiting default account and password settings

Engineering Contradiction:
Improvenetwork accessVSAvoidrogue access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing security measures (changing default passwords, configuring digital certificates, restricting account access) before the server is connected to the network. This preemptive approach prevents rogue software from exploiting default credentials, as the security vulnerabilities are eliminated before network exposure occurs.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent ensures that security configuration actions are completed before network connection. The service processor is secured with unique credentials and access restrictions in place before the server gains network access, thereby preventing any window of vulnerability where rogue software could exploit default settings.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If proximity-based connection with digital certificate is used, then secure access is enabled without direct network exposure, but requires additional securing step before network connection

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses proximity-based connections (such as Bluetooth or NFC) as an intermediary method to transfer digital certificates and security configurations from a management system to the server's service processor. This intermediary approach allows secure configuration without requiring the server to be connected to the network, while the digital certificate acts as a secure credential that simplifies subsequent management access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9838378B2Securing a server before connecting the server to a data communications network
Publication Date: 2017.12.05 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9838378B2 patent drawing
  • US9838378B2 patent drawing
  • US9838378B2 patent drawing

AI summary

Securing a server before connecting the server to a data communications network in a data center may include: establishing a proximity-based communications connection with a service processor of a server, where the server is not coupled to a data communications network; and transmitting, via the proximity-based data communications connection, a digital certificate to the service processor of the server, where the digital certificate is configured to enable access to the server only by a system management server.