Trusted Orchestrator BIOS Inventory Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Logically Composed Systems (LCS), the management device relies on the trusted orchestrator for an inventory of function subsystems, but situations arise where function subsystems are connected without the orchestrator's knowledge, leading to potential access issues or security concerns, as the orchestrator may not authorize all provided subsystems.

Innovation Solution

A Bare Metal Server (BMS) system with a processing system, memory, BIOS, and a trusted orchestrator device that generates function subsystem detection alerts, updates the BIOS inventory, and verifies if the subsystems are in a trusted inventory, allowing or preventing the operating system's access accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the trusted orchestrator device maintains strict gatekeeping control over function subsystems, then security is improved, but device complexity increases due to the need for inventory verification mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BIOS generates an inventory of function subsystems before the operating system accesses them, and the trusted orchestrator verifies this inventory in advance. This preliminary action ensures security requirements are met before runtime operations begin, preventing unauthorized access while maintaining system security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The BIOS acts as an intermediary between the function subsystems and the trusted orchestrator, collecting inventory information and transmitting it for verification. This intermediary role simplifies the architecture by centralizing the verification process through an existing component rather than requiring direct complex interactions between all subsystems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the BIOS generates detailed inventory updates for all function subsystems, then measurement precision is improved, but loss of time increases due to the overhead of continuous monitoring and reporting

Engineering Contradiction:
Improveinventory accuracyVSAvoidtime
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system generates inventory updates selectively rather than continuously monitoring all function subsystems at all times. The BIOS generates inventory information in response to specific events or at scheduled intervals, providing sufficient accuracy for security verification without the time overhead of continuous comprehensive monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11983273B2Trusted orchestrator function subsystem inventory and verification system
Publication Date: 2024.05.14 DELL PROD LP
  • US11983273B2 patent drawing
  • US11983273B2 patent drawing
  • US11983273B2 patent drawing

AI summary

A trusted orchestrator function subsystem inventory and verification system includes an OS, a BIOS, a management device, and a trusted orchestrator device. In response to presentation of a function subsystem to the OS during runtime, the OS generates a function subsystem detection alert that identifies the function subsystem. In response to the function subsystem detection alert, the BIOS generates and provides a BIOS inventory update that identifies the function subsystem. The management device receives the BIOS inventory update and, in response, forwards the BIOS inventory update. The trusted orchestrator device receives the BIOS inventory update and, in response, determine whether the function subsystem identified in the BIOS inventory update is included in a trusted function subsystem inventory. If so, the trusted orchestrator device allows the operating system to utilize the function subsystem while, if not, the trusted orchestrator device prevents the operating system from utilizing the function subsystem.