Topology Change Authorization via Wireless Credential Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices with modified topologies, such as added or removed carrier boards, face challenges in ensuring that only authorized components are accessed, particularly in maintaining operating temperature and component compatibility, leading to potential system instability and unauthorized service access.

Innovation Solution

The implementation of a wireless credential exchange (WCE) that stores configuration data indicating an authorized stackable topology map, allowing the system to determine if changes in the topology are allowed and enabling or disabling services accordingly, ensuring only authorized components are accessed and maintaining system stability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the system allows dynamic addition or removal of carrier boards to improve adaptability, then the versatility of the computing device is improved, but the risk of unauthorized component access and system instability increases

Engineering Contradiction:
ImproveversatilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary verification of carrier board authorization before allowing access to services. The BIOS detects topology changes and checks against authorized configuration data stored in secure storage, preventing unauthorized components from accessing the system before they can cause instability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary authorization checking mechanism is introduced between the carrier board and service access. The system uses configuration data stored in secure storage and verified by the BIOS as an intermediary layer to mediate access requests, ensuring only authorized components can access services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements strict authorization checks to maintain system stability, then reliability is improved, but the complexity of the access control mechanism increases

Engineering Contradiction:
Improvesystem stabilityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses self-service authorization where the carrier board itself contains identification information (such as embedded controllers or identification circuits) that automatically present themselves during topology detection. The BIOS autonomously verifies this information against stored configuration data without requiring external intervention, simplifying the access control process

Inventive Principle:
Principle #25Self-service

3Reliability

If the system stores configuration data in secure storage to prevent unauthorized access, then security is improved, but the difficulty of detecting and measuring authorized topology changes increases

Engineering Contradiction:
ImprovesecurityVSAvoidtopology change detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms where the BIOS continuously monitors system topology and compares detected changes against authorized configuration data stored in secure storage. When topology changes occur, the system provides feedback by checking authorization status and either permitting or blocking access based on the verification result

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The configuration data is segmented into specific authorization parameters that can be individually checked. The BIOS detects topology changes by segmenting the verification process into discrete steps: detecting the change, extracting authorization information from secure storage, verifying the specific component, and making an access decision

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10251060B2Modifying access to a service based on configuration data
Publication Date: 2019.04.02 INTEL CORP
  • US10251060B2 patent drawing
  • US10251060B2 patent drawing
  • US10251060B2 patent drawing

AI summary

In one example, a system for accessing services comprises a processor to detect a change in a topology of the system and request configuration data or a firmware image stored in secure storage of a wireless credential exchange or EEPROM, wherein the configuration data indicates an authorized stackable topology map for the system. The processor can also determine the change in the topology is allowed based on the authorized stackable topology map and execute an internet or local based service comprising a modification based on the change to the topology of the system, the service with the modification to be executed in response to a transmission of the change to the service.