IP Library Granted Patent US 11,477,026
Granted Patent B1
US 11,477,026 · App. 16/999,783 · Granted Oct 18, 2022

Using secure tokens for stateless software defined networking

Inventors: Robert Walter Schumann, III (Ashburn, VA); Donald Bradley Wood (Nashville, TN); Marlin Popeye McFate (Dumfries, VA); Michael Clayton Rudd (Katy, TX); Mircea I. T. Zetea (Feleacu, RO); Carlos Marcelo Rodriguez de Luna (Magnolia, TX)
Assignee: Riverbed Technology, Inc.
H04L9/3213H04L9/3226H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,026
App. No.
16/999,783
Granted
Oct 18, 2022
Kind
B1
Abstract

Systems and techniques are described to facilitate using secure tokens for stateless software defined networking. An initial configuration may be created for deploying a network device at a deployment site. A cryptographically secure certificate may be created that includes the initial configuration for deploying the network device at the deployment site. The cryptographically secure certificate may be stored in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the device at the deployment site. The network device may then be configured at the deployment site by using the secure token.

Claims (35)

1. A method, comprising:

creating an initial configuration for deploying a network device at a deployment site;

creating, by a processor, a cryptographically secure certificate that includes the initial configuration for deploying the network device at the deployment site;

storing the cryptographically secure certificate in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the network device at the deployment site;

inserting the secure token into the secure token reader that is located at the deployment site and communicatively coupled to the network device at the deployment site;

extracting the initial configuration from the cryptographically secure certificate stored in the secure token;

configuring the network device using the initial configuration, wherein the initial configuration enables the network device to securely communicate with a controller; and

establishing a secure communication channel between the network device and the controller, wherein said establishing the secure communication channel between the network device and the controller comprises authenticating the network device with the controller, wherein said authenticating the network device with the controller comprises the network device proving an Internet Protocol (IP) address of the network device, a Global Position System (GPS) coordinate of the network device, and a Public Key Infrastructure (PKI) certificate to the controller.

2. The method of claim 1 , wherein the initial configuration comprises a unique identifier.

3. The method of claim 2 , wherein the initial configuration comprises an interface identifier of a network interface of the network device.

4. The method of claim 3 , wherein the initial configuration comprises an Internet Protocol (IP) address and an IP mask of the network device.

5. The method of claim 4 , wherein the initial configuration comprises an IP address of default gateway.

6. The method of claim 5 , wherein the initial configuration comprises an IP address of a Domain Name System (DNS) server.

7. The method of claim 6 , wherein the initial configuration comprises an IP address or a Uniform Resource Locator (URL) of a controller.

8. The method of claim 1 , wherein said extracting the initial configuration from the cryptographically secure certificate stored in the secure token comprises prompting a user to enter a pin code.

9. The method of claim 1 , comprising downloading a deployment configuration from the controller over the secure communication channel.

10. The method of claim 9 , comprising configuring the network device using the deployment configuration, where the deployment configuration enables the network device to operate with a desired functionality at the deployment site.

11. The method of claim 1 , wherein the secure token reader that is located at the deployment site is communicatively coupled to the network device by a wired communication cable.

12. The method of claim 11 , wherein the wired communication cable is a Universal Serial Bus (USB) cable.

13. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to:

create an initial configuration for deploying a network device at a deployment site;

create a cryptographically secure certificate that includes the initial configuration for deploying the network device at the deployment site; and

store the cryptographically secure certificate in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the network device at the deployment site;

extract the initial configuration from the cryptographically secure certificate stored in the secure token;

configure the network device using the initial configuration, wherein the initial configuration enables the network device to securely communicate with a controller; and

establish a secure communication channel between the network device and the controller, wherein said establishing the secure communication channel between the network device and the controller comprises authenticating the network device with the controller, wherein said authenticating the network device with the controller comprises the network device proving an Internet Protocol (IP) address of the network device, a Global Position System (GPS) coordinate of the network device, and a Public Key Infrastructure (PKI) certificate to the controller.

14. A system, comprising:

a controller comprising a first processor and a first memory, the first memory storing instructions that, when executed by the first processor, cause the controller to create an initial configuration for deploying a network device at a deployment site;

a certificate manager comprising a second processor and a second memory, the second memory storing instructions that, when executed by the second processor, cause the certificate manager to create a cryptographically secure certificate that includes the initial configuration for deploying the network device at the deployment site; and

a secure token manager comprising a third processor and a third memory, the third memory storing instructions that, when executed by the third processor, cause the secure token manager to store the cryptographically secure certificate in a secure token that can be inserted into a secure token reader that is located at the deployment site and communicatively coupled to the network device at the deployment site;

a secure token reader located at the deployment site and communicatively coupled to the network device at the deployment site, the secure token receiver to:

receive the secure token,

extract the initial configuration from the cryptographically secure certificate stored in the secure token, and

configure the network device using the initial configuration, wherein the initial configuration enables the network device to securely communicate with a controller; and

the network device to establish a secure communication channel between the network device and the controller, wherein said establishing the secure communication channel between the network device and the controller comprises authenticating the network device with the controller, wherein said authenticating the network device with the controller comprises the network device proving an Internet Protocol (IP) address of the network device, a Global Position System (GPS) coordinate of the network device, and a Public Key Infrastructure (PKI) certificate to the controller.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2022
From: SCHUMAN III, ROBERT WALTER; WOOD, DONALD BRADLEY; MCFATE, MARLIN POPEYE; RUDD, MICHAEL CLAYTON; ZETEA, MIRCEA I.T.; DE LUNA, CARLOS MARCELO RODRIGUEZ
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 059091/0378 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
Continuity (2)
Provisional Application 62990968 · Mar 17, 2020
Provisional Application 62889928 · Aug 21, 2019