Service Processor Access via QR Code Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing authentication methods for accessing service processors are insecure, particularly for remote management of multiple server computers, as they often require bulky peripheral devices that can be lost or stolen, and do not effectively manage varying access permissions among users.

Innovation Solution

A system and method that uses a web-based access mechanism where users enter IPMI credentials, and if advanced login is enabled, a QR code is displayed, which is captured by a smartphone to generate a PIN for secure access to the service processor, ensuring only authorized users can access management functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional RFID cards are used for user authentication, then user identification can be achieved, but the system requires bulky peripheral devices that can be lost or stolen

Engineering Contradiction:
Improveauthentication securityVSAvoidperipheral device requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from bulky peripheral RFID devices and integrates it into the service processor itself. The service processor now directly handles authentication without requiring external reading devices, eliminating the need for complex peripheral hardware while maintaining security through embedded cryptographic capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a web-based authentication interface as an intermediary between the user and the service processor. This web interface handles the complex authentication logic and communication, simplifying the user experience while maintaining secure authentication through the service processor's embedded security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional RFID authentication is used, then user access can be controlled, but the devices are portable and subject to being lost or stolen

Engineering Contradiction:
Improveuser access controlVSAvoiddevice loss and theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent merges the authentication credentials directly into the service processor's secure memory rather than using portable RFID cards. The service processor stores authentication data locally and performs verification internally, combining the functions of credential storage and verification in a single secure location that cannot be easily removed or stolen.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses web-based authentication that allows users to access the service processor through a browser interface, creating a virtual copy of the authentication experience. This eliminates the need for physical RFID cards while maintaining the ability to control and track user access through the web interface.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple users require access to service processor, then management functions can be performed, but varying access permissions are difficult to manage

Engineering Contradiction:
Improvemulti-user accessVSAvoidaccess permission management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control through the web interface, where user permissions can be adjusted without changing physical hardware or reconfiguring the system architecture. The service processor can dynamically grant or revoke access rights based on user identity and predefined policies, allowing flexible management of multiple users with different permission levels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal authentication framework that handles multiple user types and permission levels through a single web-based interface. This unified approach allows the service processor to serve multiple users with varying access rights without requiring separate authentication mechanisms for each user type, simplifying the overall system while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8904507B2System and method for controlling user access to a service processor
Publication Date: 2014.12.02 AMERICAN MEGATRENDS
  • US8904507B2 patent drawing
  • US8904507B2 patent drawing
  • US8904507B2 patent drawing

AI summary

According to one aspect, a system for managing user access to a service processor is disclosed. In one embodiment, the system includes a computer-executable management access module for performing functions to authenticate a user. A management computer that is communicatively coupled to the service processor is operative to perform management functions for at least one target computer. User authentication functions include receiving a first set of login data from a user of the management computer and verifying whether the received login data corresponds to an approved user. If the first set of login data corresponds to an approved user, a code is generated and then displayed on the management computer. When recognized by the personal computing device, data from the code is used for providing a second set of login information to the user, for permitting the user to access the service processor via the management computer.