IP Library Granted Patent US 8,621,567
Granted Patent B2
US 8,621,567 · App. 11/198,834 · Granted Dec 31, 2013

Network security and applications to the fabric environment

Inventors: James Kleinsteiber (San Jose, CA); Richard L. Hammons (Hollister, CA); Dilip Gunawardena (Redwood Shores, CA); Hung Nguyen (San Jose, CA); Shankar Balasubramanian (Sunnyvale, CA); Vidya Renganararayanan (Santa Clara, CA)
Assignee: Brocade Communications Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,621,567
App. No.
11/198,834
Granted
Dec 31, 2013
Kind
B2
Abstract

A method and apparatus for securing networks, focusing on application in Fibre Channel networks. A combination of unique security techniques are combined to provide overall network security. Responsibility for security in the network is assigned to one or more designated entities. The designated entities deploy management information throughout the network to enhance security by modifying the capabilities and operational permissions of the devices participating in the network. For example, through network control: logical management access or physical I/O access may be limited on a per device or per I/O basis; and all devices and ports in the network operate only with other approved devices and ports. These designated entities can better manage network security by exploiting a unique link authentication system as well as a unique push-model secure distributed time service. The link authentication involves a multi-phase nonce exchange exploiting various derivations of the nonce and other information such as hashes and encryptions. The push-model secure time distribution departs from the traditional Fibre Channel pull mode time distribution and provides for secure and reliable distributed time so that various security attacks may be defeated.

Claims (20)

1. A method of securing a network comprising the steps of:

limiting access to a first set of one or more network management functions relating to the capabilities and operational permissions of devices in the network by allowing control of said first set of network management functions only through one or more pre-selected devices; and

limiting access to a second set of network management functions relating to the capabilities and operational permissions of devices in the network to access only through one or more pre-determined logical channels of said one or more pre-selected devices as specified by a network operator;

wherein the first set of network management functions is mutually exclusive from the second set of network management functions.

2. The method of claim 1 , further comprising the step limiting communication to that occurring between pre-defined pairs of said devices.

3. The method of claim 1 , further comprising the step of limiting devices in the logical network to those on a pre-defined list of allowed devices.

4. The method of claim 1 where there is only one pre-selected device.

5. The method of claim 1 wherein said pre-selected devices are all located in controlled-access environments.

6. The method of claim 1 further comprising the step of providing a distributed time service.

7. A network device comprising:

a processor;

a memory; and

an input/output interface complex;

wherein the processor is programmed to limit access to a first set of one or more network management functions relating to the capabilities and operational permissions of devices in the network through the network device as specified by a network operator; and

wherein the processor is further programmed to limit access to a second set of network management functions relating to the capabilities and operational permissions of devices in the network to access only through one or more pre-determined logical channels of the network device as specified by a network operator; and

wherein the first set of network management functions is mutually exclusive from the second set of network management functions.

8. The network device of claim 7 wherein the network device is a switch.

9. The network device of claim 7 wherein the network device is programmed to exclude other network devices from access to the first and second set of network management functions.

10. The network device of claim 7 wherein the network device is located in a controlled-access environment.

11. The network device of claim 7 wherein the network device is configured to provide a distributed time service.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: BROCADE COMMUNICATIONS SYSTEMS LLC
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047270/0247 →
CHANGE OF NAME Recorded Dec 13, 2017
From: BROCADE COMMUNICATIONS SYSTEMS, INC.
To: BROCADE COMMUNICATIONS SYSTEMS LLC
Reel/Frame 044891/0536 →
RELEASE OF SECURITY INTEREST Recorded Jan 22, 2015
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC
Reel/Frame 034804/0793 →
RELEASE OF SECURITY INTEREST Recorded Jan 21, 2015
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; INRANGE TECHNOLOGIES CORPORATION; FOUNDRY NETWORKS, LLC
Reel/Frame 034792/0540 →
SECURITY AGREEMENT Recorded Jan 20, 2010
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION; MCDATA SERVICES CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 023814/0587 →
SECURITY AGREEMENT Recorded Dec 22, 2008
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, INC.; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION
To: BANK OF AMERICA, N.A. AS ADMINISTRATIVE AGENT
Reel/Frame 022012/0204 →
Continuity (2)
Division 10062125 · Jan 31, 2002
Related Publication 20060005233A1 · Jan 5, 2006