Virtual Media Gateway for Private Network IHS Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing Information Handling Systems (IHSs) configured on private networks using a systems management console accessible via a publicly accessible network is challenging due to restricted access and the need for seamless user authentication across multiple IHSs in a data center.

Innovation Solution

A virtual media gateway system that establishes a first login session with a public network and authenticates with IHSs on behalf of the user to create a second login session through a private network, enabling user interaction and management of IHSs via a systems management console.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a systems management console is remotely configured to manage IHSs in a data center, then comprehensive lifecycle management can be facilitated from one console, but the console cannot directly access IHSs on private networks due to network security restrictions

Engineering Contradiction:
ImproveAbility to manage IHSs across different network typesVSAvoidNetwork security restrictions blocking access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A virtual media gateway is introduced as an intermediary component that bridges the public network where the systems management console operates and the private network where IHSs are located. The gateway establishes secure tunnels and handles authentication, allowing the console to manage IHSs without direct access to the private network, thus maintaining security while enabling versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If direct access to IHSs on private networks is allowed from the systems management console, then seamless user authentication and management can be achieved, but network security and domain isolation are compromised

Engineering Contradiction:
ImproveUser authentication and managementVSAvoidNetwork security and domain isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network architecture is segmented into distinct zones: a public network zone for the systems management console, a private network zone for IHSs, and a virtual media gateway zone that connects them. This segmentation allows easy operation within each zone while maintaining security boundaries, as the gateway handles cross-zone communication securely without compromising domain isolation.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If the systems management console establishes direct connections to multiple IHSs, then user interaction with each device can be provided, but the complexity of managing multiple authentication sessions increases

Engineering Contradiction:
ImproveUser interaction with computing devicesVSAvoidAuthentication session management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Multiple authentication sessions to different IHSs are merged and managed through a single virtual media gateway. The gateway consolidates authentication credentials and session management, allowing the systems management console to interact with multiple IHSs without handling individual authentication complexities for each device, thus simplifying operation while reducing session management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11722569B1System and method for providing a virtual media gateway using a systems management console
Publication Date: 2023.08.08 DELL PROD LP
  • US11722569B1 patent drawing
  • US11722569B1 patent drawing
  • US11722569B1 patent drawing

AI summary

Embodiments of the present disclosure provide a system and method for providing a virtual media gateway in which an Information Handling Systems (IHSs) configured on a private network may be managed using a systems management console. One embodiment of the virtual media gateway system includes a systems manager in communication with multiple server IHSs configured in a data center. The systems manager includes executable code to establish a first login session with a public network configured in the data center, and using the first login session, receive a request to communicate with one of the computing devices. The executable code is further executable to authenticate the systems manager with the one server IHS on behalf of the end-user to establish a second login session through a private network, and generate a console for providing user interaction with the one computing device via the second login session.