Trust Domain Engine for Automated Hyper-Converged Infrastructure Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional hyper-converged infrastructure deployment and management systems face challenges with automated configuration and management due to varying device credentials, model/generation differences, and lack of pre-installed certificates, leading to increased time and costs in deployment and management.
Innovation Solution
A computing device infrastructure trust domain system that uses a trust domain engine to securely manage and authenticate devices by broadcasting and verifying component hash values, eliminating the need for credentials or certificates, and allowing secure deployment and management through external consoles and custom scripts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional automated deployment tools use predefined authentication mechanisms with target credentials, then authentication to target devices is enabled, but the system cannot handle devices with random management controller passwords or different default credentials that differ by model, generation, or operating system version
Solution Approach 1:
The system enables devices to authenticate themselves by broadcasting their own component hash values and authentication information. The management system automatically verifies these broadcasts against stored expected values, eliminating the need for manual credential provision or pre-configured authentication mechanisms on each device.
Solution Approach 2:
The management system pre-stores expected component hash values and authentication information for devices before deployment. This preliminary preparation allows the system to automatically verify incoming device broadcasts without requiring real-time credential configuration or manual authentication setup.
2Reliability
If manual deployment or credential update tools are used, then deployment can be performed, but time and costs increase
Solution Approach 1:
The patent replaces manual mechanical operations (physically configuring devices, manually updating credentials) with an automated electronic broadcast and verification system. Devices electronically broadcast their component hash values, and the management system automatically compares these against stored expected values, eliminating manual intervention entirely.
Solution Approach 2:
The system implements a feedback mechanism where devices broadcast their current component hash values and authentication information, the management system verifies these broadcasts against expected values, and automatically accepts or rejects devices based on this feedback. This closed-loop verification ensures reliable deployment while maintaining automation.
3Ease of operation
If conventional authentication mechanisms are used, then authentication can be performed, but the system cannot securely manage devices without pre-installed certificates or with varying default credentials
Solution Approach 1:
The patent extracts the authentication information and component hash values directly from the devices themselves during their initialization or registration process. These extracted values are stored in the management system and used for subsequent authentication, eliminating the need for complex certificate-based mechanisms or pre-installed authentication software on each device.
Solution Approach 2:
The management system uses a universal broadcast and verification mechanism that works across different device types, models, and generations. The same basic process of broadcasting component hash values and authentication information applies to all devices, regardless of their specific hardware configuration or firmware version, simplifying the overall authentication architecture.
Data Source
AI summary
A computing device infrastructure trust domain system includes first and second computing devices included in a computing device infrastructure system. The second computing device stores authentication information specific to the computing device infrastructure system, and operates to receive a first communication broadcast by the first computing device, verify that the first communication includes the authentication information and, in response, add the first computing device to a trust domain and store a first computing device component hash value included in the first communication. When the second computing device subsequently receives a second communication from the first computing device, it determines whether the second communication includes the first computing device component hash value: If so, the second computing device removes the first computing device from the trust domain, if not, the second computing device performs at least one trust domain operation associated with the first computing device.


