Service Processor Gateway Consolidating Management Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high cost and complexity of deploying service processor technologies in computer and telecommunication systems due to the need for additional Ethernet connections and management overhead, as well as security concerns related to exposing management protocols to the data network, hinder their widespread adoption.

Innovation Solution

A service processor gateway system that provides point-to-point Ethernet connections and terminates management sessions locally, eliminating the need for dedicated network addresses and exposing management protocols to the data network, using secure protocols like SSH, SSL, and XML for consolidated information transport.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated Ethernet connections are provided for each service processor, then remote management access is enabled, but deployment cost and network complexity increase

Engineering Contradiction:
Improveremote management accessVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A gateway device is introduced as an intermediary between the service processors and the network. The gateway consolidates multiple service processor connections into a single network interface, enabling remote management access while eliminating the need for dedicated Ethernet connections for each service processor. This mediator approach resolves the contradiction by providing the necessary connectivity without the associated complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If service processor protocols are exposed to the data network, then management functionality is accessible, but security vulnerabilities increase

Engineering Contradiction:
Improvemanagement accessibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway acts as a security intermediary that terminates service processor protocols before they reach the data network. It translates these protocols into secure network-compatible protocols (such as SSH, SSL, or HTTPS), enabling management accessibility while preventing direct exposure of vulnerable service processor protocols to the network. This resolves the security vulnerability issue while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple network addresses are allocated for service processors, then individual access is enabled, but network management overhead increases

Engineering Contradiction:
Improveindividual access capabilityVSAvoidnetwork management overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway consolidates multiple service processor connections into a single network interface, merging the need for multiple network addresses into one. This combining approach maintains the ability to individually access each service processor through the gateway while eliminating the overhead of managing multiple network addresses, thus resolving the contradiction between adaptability and management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7466713B2Service processor gateway system and appliance
Publication Date: 2008.12.16 VERTIV CORP
  • US7466713B2 patent drawing
  • US7466713B2 patent drawing
  • US7466713B2 patent drawing

AI summary

A system for physically consolidating and securing access to service processors and management modules in computer, telecommunication and networking equipment is provided that isolates the management ports from the data network. The system converts low-level management protocols into higher-level network protocols suitable for secure transport over the data network. The system may encrypt the common format management data. The system may also authenticate each user that attempts to access the management interfaces.