IP Library › Granted Patent US 12,425,399
Granted Patent B2
US 12,425,399 · App. 17/701,299 · Granted Sep 23, 2025

Distributed hierarchical authentication of system component identities

Inventors: Archana Nagaraj (San Ramon, CA); Chandana Prakash (Dublin, CA); Michael Gary Curcio (Apex, NC); Rachel Weeks (Oak Ridge, TN)
Assignee: Cisco Technology, Inc.
H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,399
App. No.
17/701,299
Granted
Sep 23, 2025
Kind
B2
Abstract

In an example method, a presence of a component with a cryptographic identity is detected. The component is detected by an authenticator component capable of authenticating a component. The example method further includes determining an authentication status of the detected component. The authentication status of the component is added to an extensible list of volatile, runtime data. Further, the authenticator component signs the extensible list with a private key to create a group identity. Finally, the authenticator component sends the group identity to a next higher component in an authentication hierarchy.

Claims (55)

1. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform acts comprising:

storing, by a first authenticator component, an indication that a component having a cryptographic identity is currently associated with a component group in an authentication hierarchy of component groups, the component group comprising the component and a second authenticator component capable of authenticating the component;

receiving, by the first authenticator component, a first group identity from the second authenticator component, the first group identity including: (i) an identity of the second authenticator component and the component, (ii) an authentication status of the component, the authentication status indicating whether the component is valid, invalid, or unsupported, and (iii) a digital certificate of the second authenticator component;

verifying, by the first authenticator component, the first group identity, wherein verifying the first group identity comprises determining the digital certificate of the second authenticator component is valid;

storing, by the first authenticator component, information associated with the second authenticator component and the component in an extensible list of volatile, runtime data;

signing, by the first authenticator component, the extensible list with a private key to create a second group identity; and

sending the second group identity to a next higher authenticator component in the authentication hierarchy.

2. The system of claim 1 , wherein the component is a first component and the acts further comprising:

storing an indication that a second component having a second cryptographic identity is currently associated with the component group;

receiving, by the first authenticator component, the first group identity from the second authenticator component, the first group identity including: (i) the identity of the second authenticator component, the first component, and the second component, authentication status of the first component and the second component, the authentication status indicating whether the first component and the second component are valid, invalid, or unsupported;

verifying, by the first authenticator component, the first group identity; and

storing information associated with the second authenticator component, the first component, and the second component in the extensible list of volatile, runtime data.

3. The system of claim 1 , wherein verifying the first group identity comprises determining that the second authenticator component has a valid authentication status.

4. The system of claim 1 , wherein the information stored in the extensible list comprises a component location ID, an authentication status, a product identifier (PID), and a serial number (SN) for each authenticated component in the system.

5. The system of claim 1 , the acts further comprising creating a table populated with information relating to authenticated components listed in the extensible list and outputting the table to an administrator device.

6. The system of claim 1 , the acts further comprising:

receiving, by the first authenticator component, a third group identity from an authenticator component comprising information relating to a change in a component in a component group;

verifying, by the first authenticator component, the third group identity; and

updating, by the first authenticator component, the extensible list with information relating to the change.

7. The system of claim 6 , wherein the change comprises at least one of:

a component removed from a location;

a component added to a location; or

a component removed from one location and added to a different location.

8. The system of claim 1 , wherein an authenticator component is periodically polled to determine if a change relating to a component in a component group has occurred.

9. The system of claim 1 , wherein the component having the cryptographic identity is one of a Small Form-factor Pluggable (SFP) optical transceiver, a hot-swappable/redundant power supply, or a fan tray.

10. The system of claim 1 , wherein the component having the cryptographic identity is a software component.

11. A method comprising:

storing, by a first authenticator component, an indication that a component having a cryptographic identity is currently associated with a component group in an authentication hierarchy of component groups, the component group comprising the component and a second authenticator component capable of authenticating the component;

receiving, by the first authenticator component, a first group identity from the second authenticator component, the first group identity including: (i) an identity of the second authenticator component and the component, (ii) an authentication status of the component, the authentication status indicating whether the component is valid, invalid, or unsupported, and (iii) a digital certificate of the second authenticator component;

verifying, by the first authenticator component, the first group identity, wherein verifying the first group identity comprises determining the digital certificate of the second authenticator component is valid;

storing, by the first authenticator component, information associated with the second authenticator component and the component in an extensible list of volatile, runtime data;

signing, by the first authenticator component, the extensible list with a private key to create a second group identity; and

sending the second group identity to a next higher authenticator component in the authentication hierarchy.

12. The method of claim 11 , wherein the component having the cryptographic identity is a software component.

13. The method of claim 11 , wherein the information stored in the extensible list comprises a component location ID, an authentication status, a product identifier (ID), and a serial number (SN) for each authenticated component in a system.

14. The method of claim 11 , further comprising creating a table populated with information relating to authenticated components listed in the extensible list and outputting the table to an administrator device.

15. The method of claim 11 , further comprising:

receiving, by the first authenticator component, a third group identity from an authenticator component comprising information relating to a change in a component in a component group;

verifying, by the first authenticator component, the third group identity; and

updating, by the first authenticator component, the extensible list with information relating to the change.

16. The method of claim 15 , wherein the change comprises at least one of:

a component removed from a location;

a component added to a location; or

a component removed from one location and added to a different location.

17. The method of claim 11 , wherein an authenticator component is periodically polled to determine if a change relating to a component in a component group has occurred.

18. The method of claim 11 , wherein the component having the cryptographic identity is one of a Small Form-factor Pluggable (SFP) optical transceiver, a hot-swappable/redundant power supply, or a fan tray.

19. One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform acts comprising:

storing, by a first authenticator component, an indication that a component having a cryptographic identity is currently associated with a component group in an authentication hierarchy of component groups, the component group comprising the component and a second authenticator component capable of authenticating the component;

receiving, by the first authenticator component, a first group identity from the second authenticator component, the first group identity including: (i) an identity of the second authenticator component and the component, (ii) an authentication status of the component, the authentication status indicating whether the component is valid, invalid, or unsupported, and (iii) a digital certificate of the second authenticator component;

verifying, by the first authenticator component, the first group identity, wherein verifying the first group identity comprises determining the digital certificate of the second authenticator component is valid;

storing, by the first authenticator component, information associated with the second authenticator component and the component in an extensible list of volatile, runtime data;

signing, by the first authenticator component, the extensible list with a private key to create a second group identity; and

sending the second group identity to a next higher authenticator component in the authentication hierarchy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: NAGARAJ, ARCHANA; PRAKASH, CHANDANA; CURCIO, MICHAEL GARY; WEEKS, RACHEL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059343/0825 →
Continuity (1)
Related Publication 20230308439A1 · Sep 28, 2023
References Cited (25)
US 20080270790A1 · Brickell · 2008 [cited by examiner]
US 20090113219A1 · Aharonov et al. · 2009 [cited by applicant]
US 20100071024A1 · Eyada · 2010 [cited by applicant]
US 20110320599A1 · Matsumoto · 2011 [cited by examiner]
US 20130054960A1 · Grab · 2013 [cited by examiner]
US 20140082353A1 · Everhart · 2014 [cited by examiner]
US 20150169875A1 · Ide · 2015 [cited by examiner]
US 20170085568A1 · Rolfe et al. · 2017 [cited by applicant]
US 20180041341A1 · Gulati · 2018 [cited by examiner]
US 20180191501A1 · Lindemann · 2018 [cited by applicant]
US 20180234410A1 · Lindemann · 2018 [cited by examiner]
US 20180270051A1 · Roth et al. · 2018 [cited by applicant]
US 20180351944A1 · Cho · 2018 [cited by examiner]
US 20190207962A1 · Wang · 2019 [cited by examiner]
US 20220124086A1 · Gao · 2022 [cited by examiner]
US 20220141041A1 · Parikh · 2022 [cited by examiner]
US 20230239165A1 · Young · 2023 [cited by examiner]
US 20240104213A1 · Edwards · 2024 [cited by examiner]
EP 3940470A1 · 2022 [cited by examiner]
WO WO2010102259A2 · 2010 [cited by examiner]
WO WO2011146305A2 · 2011 [cited by examiner]
WO WO2016058306A1 · 2016 [cited by examiner]
WO WO2017016318A1 · 2017 [cited by examiner]
WO WO2018044282A1 · 2018 [cited by examiner]
The PCT Search Report and Written Opinion mailed Jun. 6, 2023 for PCT application No. PCT/US23/15272, 10 pgs. [cited by applicant]
Cited By (1)
US 12,592,836