Service Controller Remote Access via Alternative Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in securely accessing a management controller remotely, especially when a unique random password is factory-installed but not visibly accessible to remote users, making initial access difficult without prior knowledge of the password.

Innovation Solution

The system detects remote access attempts and provides a login interface that allows alternative authentication methods, such as AO&E, service controller signature, and federated login, enabling remote access based on user input and entitlement verification, while the unique random password is displayed on the chassis for local access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unique random password is factory-installed on the service controller, then security is improved, but ease of operation deteriorates because remote users cannot access the controller without prior knowledge of the password

Engineering Contradiction:
ImprovesecurityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring the service controller with a unique random password during manufacturing, and simultaneously providing this password to remote users through alternative methods such as printing it on a label attached to the system chassis or providing it through a secure web interface. This preliminary preparation ensures that when the controller is first powered on, both local and remote users have the necessary credentials to access it without requiring prior manual configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a web-based interface as a mediator between remote users and the service controller. This web interface serves as an intermediary communication channel that allows remote users to access the controller's management functions without needing direct physical access to the device or prior knowledge of the password, thereby resolving the contradiction between security and ease of remote access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the same default password is used on all service controllers, then ease of operation is improved, but security deteriorates due to vulnerability to brute-force attacks

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making each service controller have a unique, randomly generated password specific to that individual system, rather than using a uniform default password across all controllers. This ensures that each controller has distinct authentication credentials, preventing brute-force attacks from succeeding across multiple systems simultaneously while maintaining ease of initial access through the pre-provided unique password.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the unique random password is printed on the chassis, then ease of operation is improved for local access, but security deteriorates because the password becomes publicly visible

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the password information from the physical chassis labeling and relocates it to a secure web interface that can be accessed remotely. This extraction allows the password to be made available to users without being physically exposed on the device, thereby maintaining ease of access while improving security by preventing unauthorized viewing of the password on the chassis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10321313B2Enabling remote access to a service controller having a factory-installed unique default password
Publication Date: 2019.06.11 DELL PROD LP
  • US10321313B2 patent drawing
  • US10321313B2 patent drawing
  • US10321313B2 patent drawing

AI summary

A service controller of an information handling system provides a login user interface to a remotely located user. The service controller includes a factory-installed random unique password as its default password. If the service controller is in its original state, the service controller may grant access to the remote user based on original access input that differs from the default password. If the service controller verifies the user's access entitlement, remote access may be granted to the remote user and the remote user may modifying the default password. Access may be granted to the remote user based on user input that includes the user's credentials for accessing a database of asset, owner, and entitlement information maintained by the system supplier. Access may also be granted based on original access input including or indicative of the service controller license.