Storage Equipment Trusted Connectivity Using Temporary Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems face issues with inconsistent and insecure connectivity, leading to communication difficulties, vulnerability to hacking, and limited remote management capabilities.

Innovation Solution

Establishing trusted connectivity between storage equipment and a data center through a registration process using temporary credentials, followed by zero trust connectivity to ensure secure and reliable operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional connectivity is established between storage equipment and remote entities, then basic communication capability is achieved, but security is compromised and communication reliability deteriorates

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and credential verification before establishing the connectivity channel. The connectivity client obtains temporary credentials and undergoes authentication with the data center before the actual communication channel is created, ensuring security is built into the foundation of the connection rather than added later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using temporary credentials and certificates that mediate between the storage equipment and remote entities. This intermediary layer verifies identities and establishes trusted relationships before allowing direct communication, preventing unauthorized access while enabling legitimate connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If consistent and secure connectivity is established through registration and temporary credentials, then security and communication reliability are improved, but system complexity increases

Engineering Contradiction:
Improveconnectivity consistencyVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The connectivity client is designed as a universal component that handles multiple functions including authentication, credential management, and connection establishment within a single integrated module. This multi-functional approach consolidates what could be separate complex processes into one cohesive client that manages the entire connectivity lifecycle.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service mechanisms where the connectivity client automatically obtains temporary credentials, performs authentication, and establishes connections without requiring manual intervention. The client autonomously manages its own security credentials and connection state, reducing operational complexity despite the sophisticated security protocol.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If trusted connectivity with zero trust architecture is implemented, then security against hacking is significantly improved, but ease of operation decreases

Engineering Contradiction:
Improveprotection against hackingVSAvoidremote management ease
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The zero trust connectivity system operates autonomously through the connectivity client that automatically manages authentication, credential validation, and connection maintenance. This self-service capability eliminates the need for manual security configuration and allows remote entities to manage storage equipment seamlessly without understanding the underlying security complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses an intermediary connectivity client that shields remote entities from the complexity of zero trust authentication. The client handles all security protocols, certificate validations, and credential exchanges as an intermediary layer, presenting a simple interface to remote users while implementing robust zero trust security in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250240288A1Operating storage equipment via trusted connectivity
Publication Date: 2025.07.24 DELL PROD LP
  • US20250240288A1 patent drawing
  • US20250240288A1 patent drawing
  • US20250240288A1 patent drawing

AI summary

Techniques to operate storage equipment involve, in response to a startup command, registering the storage equipment as an untrusted client at a data center through first connectivity between a connectivity client embedded within the storage equipment and the data center. The connectivity client obtains a set of temporary credentials while registering. The techniques further involve establishing second connectivity between the connectivity client and the data center based on the set of temporary credentials, the second connectivity providing stronger security than the first connectivity. The techniques further involve, after establishing the second connectivity between the connectivity client and the data center, providing trusted communications between the connectivity client and the data center through the second connectivity to manage the storage equipment.