IP Library Granted Patent US 8,515,996
Granted Patent B2
US 8,515,996 · App. 12/123,401 · Granted Aug 20, 2013

Secure configuration of authentication servers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,515,996
App. No.
12/123,401
Granted
Aug 20, 2013
Kind
B2
Abstract

Embodiments of the invention are directed to automatically populating a database of names and secrets in an authentication server by sending one or more lists of one or more names and secrets by a network management software to an authentication server. Furthermore, some embodiments provide that the lists being sent are encrypted and/or embedded in otherwise inconspicuous files.

Claims (52)

1. A method comprising:

identifying a plurality of nodes in communication with an authentication server in a network, each node identified by a node identifier;

assigning a plurality of secrets to the plurality of nodes so that each respective secret is assigned to a respective node and associated with its node identifier;

automatically generating a data structure comprising a list of associations between the assigned secrets and the node identifiers;

securing the data structure; and

sending the data structure to store in the authentication server, the authentication server using the assigned secrets to perform authentication for the plurality of nodes.

2. The method of claim 1 , further comprising integrating the data structure into an authentication server database.

3. The method of claim 1 , wherein securing the data structure comprises encrypting the data structure.

4. The method of claim 1 , wherein encrypting the data structure comprises encrypting the data structure with a password used for communications with the authentication server or a derivation thereof.

5. The method of claim 1 , wherein securing the data structure comprises embedding the data structure within a second data structure through the use of steganography.

6. The method of claim 1 , further comprising generating the plurality of secrets.

7. The method of claim 1 , wherein the assigning, generating a data structure, securing and sending are performed by an authentication management application executed at a computer that is distinct from the authentication server.

8. The method of claim 1 , further comprising associating each secret with a unique name of a node the secret is assigned to and saving the associated names in the data structure.

9. The method of claim 1 , wherein the network comprises a storage area network.

10. The method of claim 9 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

11. The method of claim 1 , further comprising:

obtaining the assigned secrets from the data structure by the authentication server.

12. A computer readable medium comprising computer executable instructions configured to cause a processor to perform a method comprising:

identifying a plurality of nodes in communication with an authentication server in a network, each node identified by a node identifier;

assigning a plurality of secrets to the plurality of nodes so that each respective secret is assigned to a respective node and associated with its node identifier;

automatically generating a data structure comprising a list of associations between the assigned secrets and the node identifiers;

securing the data structure; and

sending the data structure to store in the authentication server, the authentication server using the assigned secrets to perform authentication for the plurality of nodes.

13. The computer readable medium of claim 12 , wherein the method further comprises generating the plurality of secrets.

14. The computer readable medium of claim 12 , wherein the computer executable instructions are part of an authentication management application, and the processor is part of a computer that is distinct from the authentication server.

15. The computer readable medium of claim 12 , wherein the method further comprises associating each secret with a unique name of a node the secret is assigned to and saving the associated names in the data structure.

16. A device comprising a processor and a memory, the memory comprising a plurality of instructions executable at the processor and configured to cause the processor to:

identify a plurality of nodes in communication with an authentication server in a network, each node identified by a node identifier;

assign a plurality of secrets to the plurality of nodes so that each respective secret is assigned to a respective node and associated with its node identifier;

automatically generate a data structure comprising a list of associations between the assigned secrets and the node identifiers;

secure the data structure; and

send the data structure to store in the authentication server, the authentication server using the assigned secrets to perform authentication for the plurality of nodes.

17. The device of claim 16 , wherein the instructions are further configured to cause the processor to generate or otherwise establish the plurality of secrets.

18. The device of claim 16 , wherein the instructions are part of an authentication management application, and the device is distinct from the authentication server.

19. The device of claim 16 , wherein the instructions are further configured to cause the processor to associate each secret with a unique name of a node the secret is assigned to and save the associated names in the data structure.

20. The device of claim 16 , wherein the network comprises a storage area network.

21. The device of claim 16 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

22. A storage area network comprising the device of claim 16 .

23. A Fibre Channel network comprising the device of claim 16 .

24. A network comprising:

a plurality of nodes;

a computer executing an authentication management application; and

an authentication server,

wherein the computer executing the authentication management application is configured to

identify a plurality of nodes in communication with the authentication serve in a network, each node identified by a node identifier;

assign a plurality of secrets to the plurality of nodes so that each respective secret is assigned to a respective node and associated with its node identifier,

automatically generate a data structure comprising a list of associations between the assigned secrets and the node identifiers,

secure the data structure, and

send the data structure to store in the authentication server; and

the authentication server is configured to

use the assigned secrets to perform authentication for the plurality of nodes.

25. The network of claim 24 , wherein the network is selected from the group consisting of a Fibre Channel network and an iSCSI network.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 047422 FRAME: 0464. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 6, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 048883/0702 →
MERGER Recorded Oct 5, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047422/0464 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041710/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037808/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2015
From: EMULEX CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 036942/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2014
From: EMULEX DESIGN AND MANUFACTURING CORPORATION
To: EMULEX CORPORATION
Reel/Frame 032087/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2008
From: HOFER, LARRY DEAN
To: EMULEX DESIGN & MANUFACTURING CORPORATION
Reel/Frame 020994/0346 →