IP Library Granted Patent US 12,206,664
Granted Patent B2
US 12,206,664 · App. 17/745,417 · Granted Jan 21, 2025

Security profile selection and configuration of network devices via ownership voucher extension

Inventors: Jabir Hamediya Mohammed (Bangalore, IN); Reda Haddad (San Jose, CA); Srihari Raghavan (Chennai, IN); Sandesh K. Rao (Fremont, CA)
Assignee: Cisco Technology, Inc.
H04L63/0876H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,664
App. No.
17/745,417
Granted
Jan 21, 2025
Kind
B2
Abstract

Techniques and architecture are described for providing a configurable security posture for a network device using an extended ownership artifact, e.g., an ownership voucher, an ownership certificate, etc., and a security profile mechanism that scales to user needs and desires for security profiles on network devices, i.e., easily and securely customizable on thousands of nodes of a network. The configurable security posture may be achieved using the manufacturer authorized signing authority (MASA) to issue an ownership voucher with a security bit extension to support security profile additions. Using the MASA service, a user may explicitly decide on various security postures of a given network device and may apply that profile across the fixed or modular chassis of a network of network devices.

Claims (51)

1. A method comprising:

providing, to a user, a first ownership artifact for a network device, wherein the first ownership artifact includes a first security profile selection bit string extension, and wherein the first security profile selection bit string extension is configured to configure the network device according to a first security profile;

receiving, from the user, a request for a second ownership artifact, wherein the request includes a request for a second security profile selection bit string extension within the second ownership artifact; and

at least in response to the request, providing the second ownership artifact to the user, wherein the second ownership artifact comprises the second security profile selection bit string extension, and wherein the second security profile selection bit string extension is configured to configure the network device according to a second security profile,

wherein the request lists only values of bits of the second security profile selection bit string extension that need to be changed to configure the network device according to the second security profile.

2. The method of claim 1 , wherein the request includes the first ownership artifact.

3. The method of claim 2 , further comprising:

based at least in part on the first ownership artifact, verifying, via a manufacturer authorized signing authority (MASA) mechanism, ownership by the user of the network device.

4. The method of claim 1 , wherein the request includes a request for a non-security profile selection bit string extension within the second ownership artifact.

5. The method of claim 1 , wherein the request for the second ownership artifact is signed by the user using the first ownership artifact.

6. The method of claim 5 , wherein a manufacturer authorized signing authority (MASA) mechanism is part of an original equipment manufacturer (OEM) that manufactured the network device.

7. The method of claim 1 , wherein the request for the second ownership artifact is based at least in part on one or more of (i) a change of ownership of the network device, (ii) different security requirements for different operational teams or business units within the user, (iii) different security requirements for different geographical regions, or (iv) new security requirements for the user.

8. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

providing, to a user, a first ownership artifact for a network device, wherein the first ownership artifact includes first security profile selection bit string extension, and wherein the first security profile selection bit string extension is configured to configure the network device according to a first security profile;

receiving, from the user, a request for a second ownership artifact, wherein the request includes a request for a second security profile selection bit string extension within the second ownership artifact; and

at least in response to the request, providing the second ownership artifact to the user, wherein the second ownership artifact comprises the second security profile selection bit string extension, and wherein the second security profile selection bit string extension is configured to configure the network device according to a second security profile,

wherein the request lists only values of bits of the second security profile selection bit string extension that need to be changed to configure the network device according to the second security profile.

9. The system of claim 8 , wherein the request includes the first ownership artifact.

10. The system of claim 9 , wherein the actions further comprise:

based at least in part on the first ownership artifact, verifying, via a manufacturer authorized signing authority (MASA) mechanism, ownership by the user of the network device.

11. The system of claim 8 , wherein the request includes a request for a non-security profile selection bit string extension within the second ownership artifact.

12. The system of claim 8 , wherein the request for the second ownership artifact is signed by the user using the first ownership artifact.

13. The system of claim 12 , wherein a manufacturer authorized signing authority (MASA) mechanism the MASA mechanism is part of an original equipment manufacturer (OEM) that manufactured the network device.

14. The system of claim 8 , wherein the request for the second ownership artifact is based at least in part on one or more of (i) a change of ownership of the network device, (ii) different security requirements for different operational teams or business units within the user, (iii) different security requirements for different geographical regions, or (iv) new security requirements for the user.

15. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:

providing, to a user, a first ownership artifact for a network device, wherein the first ownership artifact includes first security profile selection bit string extension, and wherein the first security profile selection bit string extension is configured to configure the network device according to a first security profile;

receiving, from the user, a request for a second ownership artifact, wherein the request includes a request for a second security profile selection bit string extension within the second ownership artifact; and

at least in response to the request, providing the second ownership artifact to the user, wherein the second ownership artifact comprises the second security profile selection bit string extension, and wherein the second security profile selection bit string extension is configured to configure the network device according to a second security profile,

wherein the request lists only values of bits of the second security profile selection bit string extension that need to be changed to configure the network device according to the second security profile.

16. The one or more non-transitory computer-readable media storing computer-executable instructions of claim 15 , wherein:

the request includes the first ownership artifact; and

the actions further comprise:

based at least in part on the first ownership artifact, verifying, via a manufacturer authorized signing authority (MASA) mechanism, ownership by the user of the network device.

17. The one or more non-transitory computer-readable media storing computer-executable instructions of claim 15 , wherein:

the request for the second ownership artifact is signed by the user using the first ownership artifact; and

a manufacturer authorized signing authority (MASA) mechanism is part of an original equipment manufacturer (OEM) that manufactured the network device.

18. The one or more non-transitory computer-readable media storing computer-executable instructions of claim 15 , wherein the request for the second ownership artifact is based at least in part on one or more of (i) a change of ownership of the network device, (ii) different security requirements for different operational teams or business units within the user, (iii) different security requirements for different geographical regions, or (iv) new security requirements for the user.

19. A method comprising:

providing, to a user, a first ownership artifact for a network device, wherein the first ownership artifact includes a first security profile selection bit string extension, and wherein the first security profile selection bit string extension is configured to configure the network device according to a first security profile;

receiving, from the user, a request for a second ownership artifact, wherein the request includes a request for a second security profile selection bit string extension within the second ownership artifact; and

at least in response to the request, providing the second ownership artifact to the user, wherein the second ownership artifact comprises the second security profile selection bit string extension, and wherein the second security profile selection bit string extension is configured to configure the network device according to a second security profile,

wherein the request lists (i) values of bits of the second security profile selection bit string extension that need to be changed to configure the network device according to the second security profile and (ii) current values of bits of the first security profile selection bit string extension that are to remain unchanged to configure the network device according to the second security profile.

20. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

providing, to a user, a first ownership artifact for a network device, wherein the first ownership artifact includes first security profile selection bit string extension, and wherein the first security profile selection bit string extension is configured to configure the network device according to a first security profile;

receiving, from the user, a request for a second ownership artifact, wherein the request includes a request for a second security profile selection bit string extension within the second ownership artifact; and

at least in response to the request, providing the second ownership artifact to the user, wherein the second ownership artifact comprises the second security profile selection bit string extension, and wherein the second security profile selection bit string extension is configured to configure the network device according to a second security profile, and

wherein the request lists (i) values of bits of the second security profile selection bit string extension that need to be changed to configure the network device according to the second security profile and (ii) current values of bits of the first security profile selection bit string extension that are to remain unchanged to configure the network device according to the second security profile.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: MOHAMMED, JABIR HAMEDIYA; HADDAD, REDA; RAGHAVAN, SRIHARI; RAO, SANDESH K.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060073/0497 →
Continuity (1)
Related Publication 20230370454A1 · Nov 16, 2023
References Cited (12)
US 20060143700A1 · Herrmann · 2006 [cited by examiner]
US 20170168859A1 · Watsen · 2017 [cited by applicant]
US 20180278587A1 · Daskalopoulos et al. · 2018 [cited by applicant]
US 20190274049A1 · Lee et al. · 2019 [cited by applicant]
US 20200186365A1 · Kumar et al. · 2020 [cited by applicant]
US 20200327231A1 · Smith · 2020 [cited by examiner]
US 20210352110A1 · Huffman · 2021 [cited by examiner]
US 20210367839A1 · Vanderveen · 2021 [cited by examiner]
US 20220303123A1 · Cabre · 2022 [cited by examiner]
US 20230229778A1 · Terpstra · 2023 [cited by examiner]
WO WO2019147311 · 2019 [cited by applicant]
“Secure Zero Touch Provisioning (SZTP)”, RFC 8572, Apr. 1 (Year: 2019). [cited by examiner]