IP Library Granted Patent US 9,148,412
Granted Patent B2
US 9,148,412 · App. 14/516,205 · Granted Sep 29, 2015

Secure configuration of authentication servers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,148,412
App. No.
14/516,205
Granted
Sep 29, 2015
Kind
B2
Abstract

Embodiments of the invention are directed to automatically populating a database of names and secrets in an authentication server by sending one or more lists of one or more names and secrets by a network management software to an authentication server. Furthermore, some embodiments provide that the lists being sent are encrypted and/or embedded in otherwise inconspicuous files.

Claims (29)

1. A device comprising:

a processor operable for assigning a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the respective node; and

a data structure comprising the plurality of assigned secrets and the node identifiers to which the respective secrets are associated;

wherein the device is operable to send the data structure to an authentication server, the authentication server being operable for obtaining an assigned secret of the plurality of assigned secrets from the data structure and to use the assigned secret to perform authentication for a node of the plurality of nodes.

2. The device of claim 1 , wherein the processor is operable to generate or otherwise establish the plurality of secrets.

3. The device of claim 1 , wherein the processor is operable to secure the data structure.

4. The device of claim 1 , wherein the processor is operable to encrypt the data structure.

5. The device of claim 1 , wherein the processor is operable to embed the data structure within a second data structure through the use of steganography.

6. The device of claim 1 , wherein the network comprises a storage area network.

7. The device of claim 6 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

8. A system comprising:

memory in a data structure comprising a plurality of assigned secrets and a plurality of node identifiers to which the respective secrets are associated; and

an authentication processor in an authentication server operable for obtaining an assigned secret of the plurality of assigned secrets from the data structure and to use the assigned secret to perform authentication for a node of the plurality of nodes.

9. The system of claim 8 , wherein the system comprises a processor operable to generate and assign a plurality of secrets to a plurality of nodes of a network, so that each respective secret is assigned to a respective node and associated with a node identifier of the plurality of node identifiers.

10. The system of claim 9 , wherein the processor is operable to communicate with the authentication server over the network.

11. The system of claim 9 , wherein the processor is operable to secure the data structure.

12. The system of claim 9 , wherein the processor is operable to encrypt the data structure.

13. The system of claim 9 , wherein the processor is operable to embed the data structure within a second data structure through the use of steganography.

14. The system of claim 9 , wherein the network comprises a storage area network.

15. The system of claim 14 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.

16. The system of claim 8 , wherein the authentication server is operable to decrypt the data structure.

17. A method for configuring an authentication processor in an authentication server comprising:

generating a plurality of secrets;

assigning the plurality of secrets to a plurality of nodes of a network, each secret being assigned to a node and each secret being associated with a node identifier of the respective node, thereby generating a plurality of secret assignments;

securing the plurality of secret assignments; and

communicating the secured plurality of secret assignments with an the authentication server.

18. The method of claim 17 , wherein the method comprises authenticating a node of the plurality of nodes according to a secret assignment of the plurality of secret assignments.

19. The method of claim 17 , wherein securing the plurality of secret assignments comprises encrypting the data structure.

20. The method of claim 17 , wherein securing the plurality of secret assignments comprises embedding the data structure within a second data structure through the use of steganography.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 047422 FRAME: 0464. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 6, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 048883/0702 →
MERGER Recorded Oct 5, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047422/0464 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041710/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037808/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2015
From: EMULEX CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 036942/0213 →