IP Library Granted Patent US 9,369,448
Granted Patent B2
US 9,369,448 · App. 13/170,979 · Granted Jun 14, 2016

Network security parameter generation and distribution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,448
App. No.
13/170,979
Granted
Jun 14, 2016
Kind
B2
Abstract

Disclosed are various embodiments for facilitating network security parameter distribution and generation in a converged network incorporating multiple heterogeneous link layer networking technologies. Embodiments are provided for connecting network devices through multiple heterogeneous link layer networking technologies using a converged network password. Embodiments are provided for connecting network devices through multiple heterogeneous link layer networking technologies using a pairing event protocol, such as, for example, a push button protocol.

Claims (53)

1. A system, comprising:

a plurality of network devices in data communication by way of a converged data communications network employing a plurality of heterogeneous link layer technologies; and

wherein at least one of the network devices includes a plurality of network interfaces to the converged data communications network, a first one of the network interfaces employs a first one of the heterogeneous link layer technologies, a second one of the network interfaces employs a second one of the heterogeneous link layer technologies, and the at least one of the network devices further includes network security parameter management logic that is configured to:

obtain a converged network password, the at least one network device configured to use the converged network password for pairing of each of the plurality of network interfaces to the converged data communications network using native pairing protocols associated with the network interfaces; and

connect to the converged data communications network by pairing one of the network interfaces using a native pairing protocol of a corresponding one of the heterogeneous link layer technologies based at least in part on the converged network password.

2. The system of claim 1 , wherein the network security parameter management logic is further configured to:

generate a first network password for the first one of the network interfaces based at least in part on the converged network password; and

generate a second network password for the second one of the network interfaces based at least in part on the converged network password.

3. The system of claim 2 , wherein the first network password and the second network password are each individually generated by applying a separate hash function to the converged network password.

4. The system of claim 2 , wherein the first network password is generated by applying a hash function to the converged network password, and the second network password is generated by truncating the first network password.

5. The system of claim 1 , wherein the one of the network interfaces is the first one of the network interfaces, and the network security parameter management logic is further configured to connect to the converged data communications network by pairing the second one of the network interfaces using another native paring protocol of the second one of the heterogeneous link layer technologies based at least in part on the converged network password.

6. The system of claim 1 , wherein the one of the network interfaces is the first one of the network interfaces, and the network security parameter management logic is further configured to:

obtain, by way of the first one of the network interfaces, a network security parameter for pairing the second one of the network interfaces; and

connect to the converged data communications network by pairing the second one of the network interfaces based at least in part on the network security parameter.

7. The system of claim 1 , wherein the at least one of the network devices further includes an abstraction layer configured to:

obtain a first data frame and a second data frame from a network layer;

route the first data frame to a destination by way of the first one of the network interfaces; and

route the second data frame to the destination by way of the second one of the network interfaces.

8. The system of claim 7 , wherein a media access control (MAC) address is allocated to the abstraction layer, and the MAC address is unique within the converged data communications network.

9. The system of claim 1 , wherein the at least one of the network devices further includes network security parameter distribution logic configured to:

obtain a request for a network security parameter, the request originating in another one of the network devices;

determine whether the network security parameter is associated with at least one of the network interfaces;

send the network security parameter to the other one of the network devices by way of the converged data communications network when the network security parameter is associated with the at least one of the network interfaces; and

propagate the request in the converged data communications network away from the other one of the network devices when the network security parameter is not associated with the at least one of the network interfaces.

10. A system, comprising:

a plurality of network devices in data communication by way of a converged data communications network employing a plurality of heterogeneous link layer technologies; and

a gateway device, corresponding to a first one of the network devices, the gateway device comprising network security parameter distribution logic that is configured to:

obtain a network security parameter for each of a plurality of network portions of the converged data communications network, a first one of the network portions employing a first one of the heterogeneous link layer technologies, a second one of the network portions employing a second one of the heterogeneous link layer technologies, each of the network security parameters facilitating an authenticated connection to a corresponding one of the network portions;

obtain a request for at least one of the network security parameters originating from a second one of the network devices; and

provide the at least one of the network security parameters to the second one of the network devices by way of the converged data communications network.

11. The system of claim 10 , wherein the gateway device further comprises logic that maintains a topology of the network devices connected to the converged data communications network.

12. The system of claim 10 , wherein the gateway device is configured to route data from the converged data communications network to another network.

13. The system of claim 10 , wherein the request is obtained from a third one of the network devices, and the at least one of the network security parameters is provided to the second one of the network devices by way of the third one of the network devices.

14. The system of claim 10 , wherein at least one of the network devices corresponds to a relay network device having a plurality of first network interfaces, at least one of the network devices corresponds to a terminal network device having a plurality of second network interfaces, the relay network device is configured to relay management frames and data frames between the first network interfaces, and the terminal network device is configured to relay management frames but not data frames between the second network interfaces.

15. A method, comprising:

generating, in a first one of a plurality of network devices, a pairing event;

distributing, in the first one of the network devices, the pairing event to a converged data communications network by way of a first one of a plurality of heterogeneous link layer technologies;

obtaining, in a second one of a plurality of network devices, the pairing event by way of the converged data communications network;

initiating, in the second one of the network devices, a pairing with a third one of the network devices by way of a second one of the heterogeneous link layer technologies using a native pairing event protocol of the second one of the heterogeneous link layer technologies; and

wherein the pairing is configured to connect the third one of the network devices to the converged data communications network by way of the second one of the heterogeneous link layer technologies.

16. The method of claim 15 , wherein the pairing event corresponds to a push button event, and the push button event is generated in the first one of the network devices in response to a user pushing a button of the first one of the network devices.

17. The method of claim 15 , further comprising requesting, in the third one of the network devices, a network security parameter over the converged data communications network for pairing the third one of the network devices with a fourth one of the network devices.

18. The method of claim 15 , further comprising:

generating, in the third one of the network devices, another pairing event;

sending, in the third one of the network devices, the other pairing event to the second one of the network devices by way of the second one of the heterogeneous link layer technologies; and

wherein the second one of the network devices is configured to perform the step of initiating the pairing in response to obtaining the pairing event and the other pairing event within a predefined length of time.

19. The method of claim 15 , further comprising:

obtaining, in a fourth one of a plurality of network devices, the pairing event by way of the converged data communications network;

initiating, in the fourth one of the network devices, another pairing with the third one of the network devices by way of a third one of the heterogeneous link layer technologies using a native pairing event protocol of the third one of the heterogeneous link layer technologies; and

wherein the other pairing is configured to connect the third one of the network devices to the converged data communications network by way of the third one of the heterogeneous link layer technologies.

20. The method of claim 15 , further comprising:

initiating, in the second one of the network devices, another pairing with the third one of the network devices by way of a third one of the heterogeneous link layer technologies using a native pairing event protocol of the third one of the heterogeneous link layer technologies; and

wherein the other pairing is configured to connect the third one of the network devices to the converged data communications network by way of the third one of the heterogeneous link layer technologies.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER 9,385,856 TO 9,385,756 PREVIOUSLY RECORDED AT REEL: 47349 FRAME: 001. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 22, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 051144/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE PREVIOUSLY RECORDED ON REEL 047229 FRAME 0408. ASSIGNOR(S) HEREBY CONFIRMS THE THE EFFECTIVE DATE IS 09/05/2018. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047349/0001 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047229/0408 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2011
From: KLEIN, PHILIPPE; KLIGER, AVI
To: BROADCOM CORPORATION
Reel/Frame 026629/0223 →