IP Library Granted Patent US 7,366,893
Granted Patent B2
US 7,366,893 · App. 10/213,949 · Granted Apr 29, 2008

Method and apparatus for protecting a network from attack

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,366,893
App. No.
10/213,949
Granted
Apr 29, 2008
Kind
B2
Abstract

A method and apparatus to initializing a network device is described. In one embodiment, the present invention includes the step of: retrieving an initial communications address from a local memory of the network device; transmitting a secure identifier to the initial communications address verifying the authenticity of the secure identifier; retrieving a configuration record from a configuration record repository, the retrieved configuration record being associated with the network device that corresponds to the secure identifier; receiving the configuration record at the network device; and installing the configuration record at the network device.

Claims (22)

1. A method for initializing a network device, the method comprising the steps of:

retrieving an initial communication address from a local memory of the network device;

transmitting a secure identifier to the initial communications address, the secure identifier identifying the network device;

verifying the authenticity of the secure identifier;

retrieving a configuration record from a configuration record repository, the configuration record indicating which features of the network device are to be enabled, and the configuration record repository including at least one separate configuration record for each of a plurality of network devices, each of the at least one separate configuration records enabling a corresponding one of the plurality of network devices to be reconfigured in the event an attacker alters configurations of the plurality of network devices, the retrieved configuration record being associated with the network device that corresponds to the secure identifier, each of the plurality of network devices being capable of having multiple configuration records, wherein each of the multiple configuration records for each of the plurality of network devices represents different configurations at different time frames;

receiving at least an indication of the configuration record at the network device; and

installing the at least an indication of the configuration record at the network device.

2. The method of claim 1 , further comprising the step of:

loading the network device with the initial communications address.

3. The method of claim 1 , further comprising:

loading the network device with the secure identifier.

4. The method of claim 1 , further comprising the step of:

reading a key stored on the network device; and

generating the secure identifier using the record key.

5. The method of claim 1 , wherein the secure identifier comprises:

a digital certificate.

6. The method of claim 1 , wherein the step of verifying comprises the step of:

retrieving a key from the configuration record that was retrieved from the configuration record repository, wherein the key is associated with the network device.

7. The method of claim 1 , wherein the secure identifier is a first secure identifier, the method further comprising the steps of:

receiving a second secure identifier from a network management unit;

verifying the authenticity of the received second secure identifier; and

responsive to verifying the authenticity of the second secure identifier, accepting configuration instructions for installation.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2010
From: INTELLIDEN, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 024906/0572 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2010
From: MATRIX PARTNERS VI, L.P.; MATRIX VI PARALLEL PARTNERSHIP-B, L.P.; WESTON & CO. VI, LLC; W CAPITAL PARTNERS II, L.P.; WESTBURY EQUITY PARTNERS SBIC, L.P.; GRANITE GLOBAL VENTURES II L.P.; GGV II ENTREPRENEURS FUND L.P.; AKINYEMI O. LAIUDE; SUE GERDELMAN & JOHN GERDELMAN TTEE REVOC. TRUST OF JOHN WILLIAM GERDELMAN; SUE GERDELMAN & JOHN GERDELMAN; SNOWS HILL, LLC; REMKO VOS; DALE HECHT; JAMES M. SCHNEIDER; BOYNTON FAMILY TRUST; MICHAEL J. ROWNY REVOCABLE TRUST UTA 6/6/95; BLACK FAMILY TRUST 2001 U/I DTD NOVEMBER 26, 2001; ROBERT GAFFNEY; MATRIX VI PARALLEL PARTNERSHIP-A, L.P.
To: INTELLIDEN, INC.
Reel/Frame 024053/0635 →
SECURITY AGREEMENT Recorded Apr 17, 2009
From: INTELLIDEN, INC.
To: MATRIX PARTNERS VI, L.P.; MATRIX VI PARALLEL PARTNERSHIP-A, L.P.; MATRIX VI PARALLEL PARTNERSHIP-B, L.P.; WESTON & CO. VI, LLC; KOOKABURRA LLC; WESTBURY EQUITY PARTNERS SBIC, L.P.; GRANITE GLOBAL VENTURES II L.P.; GGV II ENTREPRENEURES FUND L.P.; LALUDE, AKINYEMI O.; SUE GERDELMAN & JOHN GERDELMAN TTEE REVOC. TRUST OF JOHN WILLIAM GERDELMAN; GERDELMAN, SUE & JOHN; SNOWS HILL, LLC; VOS, REMKO; SCHNEIDER, JAMES M.; GAFFNEY, ROBERT P.; MICHAEL J. ROWNY REVOCABLE TRUST UTA; BLACK FAMILY TRUST 2001 U/I DTD; BOYNTON FAMILY TRUST BY CHARLES BOYNTON
Reel/Frame 022552/0785 →