Service Processor Access via QR Code Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, existing authentication methods for accessing service processors are insecure, particularly for remote management of multiple server computers, as they often require bulky peripheral devices that can be lost or stolen, and do not effectively manage varying access permissions among users.
Innovation Solution
A system and method that uses a web-based access mechanism where users enter IPMI credentials, and if advanced login is enabled, a QR code is displayed, which is captured by a smartphone to generate a PIN for secure access to the service processor, ensuring only authorized users can access management functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional RFID cards are used for user authentication, then user identification can be achieved, but the system requires bulky peripheral devices that can be lost or stolen
Solution Approach 1:
The patent extracts the authentication function from bulky peripheral RFID devices and integrates it into the service processor itself. The service processor now directly handles authentication without requiring external reading devices, eliminating the need for complex peripheral hardware while maintaining security through embedded cryptographic capabilities.
Solution Approach 2:
The patent introduces a web-based authentication interface as an intermediary between the user and the service processor. This web interface handles the complex authentication logic and communication, simplifying the user experience while maintaining secure authentication through the service processor's embedded security mechanisms.
2Ease of operation
If conventional RFID authentication is used, then user access can be controlled, but the devices are portable and subject to being lost or stolen
Solution Approach 1:
The patent merges the authentication credentials directly into the service processor's secure memory rather than using portable RFID cards. The service processor stores authentication data locally and performs verification internally, combining the functions of credential storage and verification in a single secure location that cannot be easily removed or stolen.
Solution Approach 2:
The patent uses web-based authentication that allows users to access the service processor through a browser interface, creating a virtual copy of the authentication experience. This eliminates the need for physical RFID cards while maintaining the ability to control and track user access through the web interface.
3Adaptability or versatility
If multiple users require access to service processor, then management functions can be performed, but varying access permissions are difficult to manage
Solution Approach 1:
The patent implements dynamic access control through the web interface, where user permissions can be adjusted without changing physical hardware or reconfiguring the system architecture. The service processor can dynamically grant or revoke access rights based on user identity and predefined policies, allowing flexible management of multiple users with different permission levels.
Solution Approach 2:
The patent creates a universal authentication framework that handles multiple user types and permission levels through a single web-based interface. This unified approach allows the service processor to serve multiple users with varying access rights without requiring separate authentication mechanisms for each user type, simplifying the overall system while maintaining versatility.
Data Source
AI summary
According to one aspect, a system for managing user access to a service processor is disclosed. In one embodiment, the system includes a computer-executable management access module for performing functions to authenticate a user. A management computer that is communicatively coupled to the service processor is operative to perform management functions for at least one target computer. User authentication functions include receiving a first set of login data from a user of the management computer and verifying whether the received login data corresponds to an approved user. If the first set of login data corresponds to an approved user, a code is generated and then displayed on the management computer. When recognized by the personal computing device, data from the code is used for providing a second set of login information to the user, for permitting the user to access the service processor via the management computer.


