IP Library Granted Patent US 8,892,602
Granted Patent B2
US 8,892,602 · App. 13/970,500 · Granted Nov 18, 2014

Secure configuration of authentication servers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,892,602
App. No.
13/970,500
Granted
Nov 18, 2014
Kind
B2
Abstract

Embodiments of the invention are directed to automatically populating a database of names and secrets in an authentication server by sending one or more lists of one or more names and secrets by a network management software to an authentication server. Furthermore, some embodiments provide that the lists being sent are encrypted and/or embedded in otherwise inconspicuous files.

Claims (43)

1. A method comprising:

assigning a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the respective node; and

generating a data structure comprising the assigned secrets and the node identifiers that the respective secrets are associated with;

wherein an authentication server is configured to obtain the assigned secrets from the data structure and to use the assigned secrets to perform authentication for the plurality of nodes.

2. The method of claim 1 , further comprising securing the data structure.

3. The method of claim 2 , wherein securing the data structure comprises encrypting the data structure.

4. The method of claim 3 , wherein encrypting the data structure comprises encrypting the data structure with a password used for communications with the authentication server or a derivation thereof.

5. The method of claim 2 , wherein securing the data structure comprises embedding the data structure within a second data structure through the use of steganography.

6. The method of claim 1 , further comprising generating the plurality of secrets.

7. The method of claim 1 , wherein the assigning and generating a data structure are performed by an authentication management application executed at a computer that is distinct from the authentication server.

8. The method of claim 1 , further comprising associating each secret with a node identifier of a node the secret is assigned to and saving the associated node identifiers in the data structure.

9. The method of claim 1 , wherein the network comprises a storage area network.

10. The method of claim 9 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

11. The method of claim 1 , further comprising integrating the data structure into an authentication server database.

12. A computer readable medium comprising computer executable instructions configured to cause a processor to perform a method comprising:

assigning a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the respective node; and

generating a data structure comprising the assigned secrets and the node identifiers that the respective secrets are associated with;

wherein an authentication server is configured to obtain the assigned secrets from the data structure and to use the assigned secrets to perform authentication for the plurality of nodes.

13. The computer readable medium of claim 12 , wherein the method further comprises generating the plurality of secrets.

14. The computer readable medium of claim 12 , wherein the computer executable instructions are part of an authentication management application, and the processor is part of a computer that is distinct from the authentication server.

15. The computer readable medium of claim 12 , wherein the method further comprises associating each secret with a node identifier of a node the secret is assigned to and saving the associated node identifiers in the data structure.

16. A device comprising a processor and a memory, the memory comprising a plurality of instructions executable at the processor and configured to cause the processor to:

assign a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the respective node; and

generate a data structure comprising the assigned secrets and the node identifiers that the respective secrets are associated with;

wherein an authentication server is configured to obtain the assigned secrets from the data structure and to use the assigned secrets to perform authentication for the plurality of nodes.

17. The device of claim 16 , wherein the instructions are further configured to cause the processor to generate or otherwise establish the plurality of secrets.

18. The device of claim 16 , wherein the instructions are part of an authentication management application, and the device is distinct from the authentication server.

19. The device of claim 16 , wherein the instructions are further configured to cause the processor to associate each secret with a node identifier of a node the secret is assigned to and save the associated node identifiers in the data structure.

20. The device of claim 16 , wherein the network comprises a storage area network.

21. The device of claim 16 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

22. A storage area network comprising the device of claim 16 .

23. A Fibre Channel network comprising the device of claim 16 .

24. A network comprising:

a plurality of nodes;

a computer executing an authentication management application; and

an authentication server,

wherein the computer executing the authentication management application is configured to

assign a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the respective node, and

generate a data structure comprising the assigned secrets and the node identifiers that the respective secrets are associated with; and

the authentication server is configured to

obtain the assigned secrets from the data structure, and

use the assigned secrets to perform authentication for the plurality of nodes.

25. The network of claim 24 , wherein the network is selected from the group consisting of a Fibre Channel network and an iSCSI network.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 047422 FRAME: 0464. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 6, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 048883/0702 →
MERGER Recorded Oct 5, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047422/0464 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041710/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037808/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2015
From: EMULEX CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 036942/0213 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2014
From: EMULEX DESIGN AND MANUFACTURING CORPORATION
To: EMULEX CORPORATION
Reel/Frame 032087/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2013
From: HOFER, LARRY DEAN
To: EMULEX DESIGN & MANUFACTURING CORPORATION
Reel/Frame 031776/0359 →