Controlling the configuration of computer systems

US9940146B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9940146-B2
Application numberUS-201514731109-A
CountryUS
Kind codeB2
Filing dateJun 4, 2015
Priority dateJan 10, 2014
Publication dateApr 10, 2018
Grant dateApr 10, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments relate to controlling configuration of a computer system comprising one or more exchangeable components. The exchangeable components comprising identification means to store an identifier. A pair of a private key and a public key are generated for each accepted manufacturer of the exchangeable components and a pair of a private key and a public key for the computer system; assigning an identifier for each exchangeable component available for attachment to the system; receiving configuration data comprising a list of encrypted identity records comprising identifiers of the components together with signatures over the data generated with the private key of the respective component manufacturer for each component expected to be attached to the system; and receiving a configuration record. The configuration data of the expected components from the received configuration record is compared with the configuration data of the components attached to the system.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for controlling configuration of a computer system, comprising one or more exchangeable components, the exchangeable components to store an identifier and provide the identifier to the computer system when being attached to it, the method comprising: generating a pair of a private key and a public key for each accepted manufacturer of the exchangeable components and a pair of a private key and a public key for the computer system; assigning an identifier for each exchangeable component available for attachment to the computer system and storing the identifier together with a signature over the identifier generated with the private key of the component manufacturer, the identifier as well as the signature being encrypted with the public key of the computer system; receiving configuration data comprising a list of encrypted identity records comprising identifiers of the components together with signatures over data generated with the private key of the respective component manufacturer for each component expected to be attached to the respective computer system, and decrypting the configuration data with the private key stored on the computer system and storing the received configuration data together with the signature; receiving a configuration record comprising the configuration data on a computer system; and in response to an attachment of the component to the computer system, sensing the configuration data of the components currently attached to the computer system, and comparing the configuration data of the exchangeable components from the received record with the configuration data of the components currently attached to the computer system, and reporting any mismatches, wherein the comparison uses the stored identifier, and verifying the signature using the public key of the component manufacturer stored in firmware of the computer system. 2. The method according to claim 1 , wherein a world-wide unique number is used as the identifier for each exchangeable component. 3. The method according to claim 2 , wherein an asynchronous process is used for encryption/decryption and signing of the identifier comprising the private key and the public key of the computer system in conjunction with signatures from each accepted manufacturer of the exchangeable components. 4. The method according to claim 3 , further comprising creating the signature for validating the identifier of the component using the private key of the component manufacturer for creating the signature of the manufacturer and/or encrypting with the public key of the computer system. 5. The method according to claim 4 , further comprising decrypting the identifier with the private key of the computer system and validating the signature on the computer system using the public key of the component manufacturer. 6. The method according to claim 2 , further comprising creating an identity record, comprising: requesting the exchangeable component by a component order; creating an identity record comprising the world-wide unique number and optional identification data of the computer system and a customer of the computer system; and signing the identity record with the signature using the private key. 7. The method according to claim 6 , wherein information from the component order comprising a system ID of the computer system is stored in the identity record. 8. The method according to claim 6 , further comprising attaching a component to the computer, comprising: reading the identity record; retrieving a system ID; decrypting with the private key of the computer system and validating the signature of the identity record with the public key of the manufacturer; importing the configuration data into a configuration database. 9. The method according to claim 8 , wherein the identity record is managed by a central order system controlling configuration for the computer system. 10. The method according to claim 9 , comprising the step of enabling components which are already attached but not enabled to the computer system. 11. The method according to claim 10 , further comprising ensuring the attachment of authorized and functional components.

Assignees

Inventors

Classifications

  • Configuring for program initiating, e.g. using registry, configuration files · CPC title

  • G06F21/73Primary

    by creating or determining hardware identification, e.g. serial numbers · CPC title

  • G06F21/44Primary

    Program or device authentication · CPC title

  • Physics · mapped topic

  • using techniques specially adapted for alterable solid state memories, e.g. for EEPROM or flash memories · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9940146B2 cover?
Embodiments relate to controlling configuration of a computer system comprising one or more exchangeable components. The exchangeable components comprising identification means to store an identifier. A pair of a private key and a public key are generated for each accepted manufacturer of the exchangeable components and a pair of a private key and a public key for the computer system; assigning…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F9/44505. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 10 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).