IP Library Granted Patent US 7,519,813
Granted Patent B1
US 7,519,813 · App. 10/910,164 · Granted Apr 14, 2009

System and method for a sidecar authentication mechanism

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,519,813
App. No.
10/910,164
Granted
Apr 14, 2009
Kind
B1
Abstract

A system and method for authenticating an unauthenticated file level protocol using a sidecar authentication mechanism. A client transmits an authentication ticket, UID and list of network addresses to an authentication daemon of a storage system. The authentication daemon verifies the user identity and generates a file system credential that is stored in a cache indexed by an authentication tuple. Received data access operations from a client are compared to authentication tuples by UID and network address and the file system utilizes the stored credential for processing the data access operation.

Claims (29)

1. A method for authenticating a file level protocol, the method comprising:

receiving a data access request using the file level protocol;

utilizing an authentication tuple to locate a file system credential;

processing the received data access request utilizing the file system credential;

generating the file system credential in response to a user executing a command on a client to transmit an authentication ticket and first UID to an authentication daemon executing within a server, the authentication ticket and first UID being transmitted over a protocol differing from the file level protocol.

2. The method of claim 1 , further comprising:

implementing the command using a multipurpose protocol protected with a multi-purpose security protocol.

3. The method of claim 2 , further comprising:

using a hypertext transfer protocol (HTTP) as the multipurpose protocol.

4. The method of claim 2 , further comprising:

using a secure sockets layer (SSL) protocol as the multipurpose security protocol.

5. The method of claim 2 , further comprising:

using a transport layer security (TLS) protocol as the multipurpose security protocol.

6. The method of claim 2 , further comprising:

including a client side agent, the client side agent including a graphical user interface in the multipurpose protocol.

7. The method of claim 6 , further comprising:

displaying the graphical user interface in a world wide web browser.

8. The method of claim 2 , further comprising:

including a client side agent in the multipurpose protocol, the client side agent including a text based interface.

9. The method of claim 8 , further comprising:

displaying the text based interface in a world wide web browser.

10. The method of claim 2 , further comprising:

including a second user identifier (UID) and a password in the authentic ticket, the second UID and password being encrypted via the multipurpose security protocol.

11. The method of claim 1 , further comprising:

implementing the command within a command line interface.

12. The method of claim 1 , further comprising:

including a Kerberos ticket in the authentic ticket.

13. The method of claim 1 , further comprising:

associating a first user with the authentication ticket and associating the first UID with a second user.

Assignments (3)
CHANGE OF NAME Recorded Jul 15, 2024
From: NETWORK APPLIANCE, INC.
To: NETAPP, INC.
Reel/Frame 067990/0556 →
CHANGE OF NAME Recorded Sep 17, 2015
From: NETWORK APPLIANCE, INC.
To: NETAPP, INC.
Reel/Frame 036591/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2004
From: COX, BENJAMIN T.H.; KAZAR, MICHAEL; NYDICK, DANIEL S.; SANZI, JR., RICHARD N.; EISLER, MICHAEL
To: NETWORK APPLIANCE, INC.
Reel/Frame 015657/0826 →