IP Library Granted Patent US 7,240,364
Granted Patent B1
US 7,240,364 · App. 09/711,054 · Granted Jul 3, 2007

Network device identity authentication

Assignee: Ciena Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,240,364
App. No.
09/711,054
Granted
Jul 3, 2007
Kind
B1
Abstract

The present invention provides a method and apparatus for authenticating the identities of network devices within a telecommunications network. In particular, multiple identifiers associated with a network device are retrieved from and used to identify the network device. Use of multiple identifiers provides fault tolerance and supports full modularity of hardware within a network device. Authenticating the identity of a network device through multiple identifiers allows for the possibility that hardware associated with one or more of the identifiers may be removed from the network device. For example, a network device may still be automatically authenticated even if more than one card within the device are removed as long as at least one card corresponding to an identifier being used for authentication is within the device during authentication. In addition, the present invention allows for dynamic authentication, that is, the NMS is able to update its records, including the identifiers, over time as cards (or other hardware) within network devices are removed and replaced.

Claims (57)

1. A method of managing a telecommunications network, comprising:

retrieving, through a management system, a current set of identifiers from a network device having at least two cards;

said identifiers comprising at least two physical identifiers and at least one logical identifier, wherein at least one of said at least two physical identifiers is associated with each of said at least two cards;

authenticating an identity of the network device using at least one of said at least two physical identifiers; and

automatically updating said management system to reflect changes made to any of said at least two physical identifiers that were not used to authenticate said network device.

2. The method of claim 1 , wherein retrieving the current set of identifiers from the network device comprises:

reading the current set of identifiers from a plurality of non-volatile memories located on a plurality of cards within the network device.

3. The method of claim 2 , wherein the plurality of non-volatile memories comprise registers.

4. The method of claim 2 , wherein the plurality of non-volatile memories comprise programmable read only memories (PROMs).

5. The method of claim 1 , wherein the management system comprises a network management system (NMS).

6. The method of claim 1 , wherein the management system comprises a command line interface (CLI).

7. The method of claim 1 , wherein prior to retrieving, through the management system, the current set of identifiers from the network device, the method further comprises:

connecting the management system to the network device using a network address assigned to the network device.

8. The method of claim 7 , wherein the network address assigned to the network device comprises an Internet Protocol (IP) address and said logical identifier comprises the IP address.

9. A method of managing a telecommunications network, comprising:

detecting a request to add a network device having at least two cards to the telecommunications network;

retrieving an initial set of at least two physical identifiers from the network device, wherein at least one of said initial set of at least two physical identifiers is associated with each of said at least two cards;

storing the initial set of identifiers in a storage unit accessible by a management system;

retrieving, through the management system, a current set of at least two physical identifiers from the network device, wherein at least one of said current set of at least two physical identifiers is associated with each of said at least two cards;

authenticating an identity of the network device using the current set of identifiers; and

updating the stored initial set of identifiers with any of the retrieved current identifiers that do not match the stored initial identifiers;

wherein said authenticating step comprises;

comparing the retrieved current set of identifiers with the stored initial set of identifiers; and

authenticating the identity of the network device if at least one of the retrieved current identifiers matches at least one of the stored initial identifiers.

10. The method of claim 9 , further comprising:

posting a user notification indicating failed authentication if at least one of the retrieved current identifiers does not match at least one of the stored initial identifiers.

11. The method of claim 10 , further comprising:

receiving a user authentication of the network device identity; and

replacing the stored initial set of identifiers with the retrieved current set of identifiers.

12. The method of claim 10 , further comprising:

detecting a user supplied new network address for the network device; and

updating a record associated with the network device with the new network address.

13. The method of claim 9 , wherein storing the initial set of identifiers comprises adding the identifiers to an Administration Managed Device table in a management system data repository.

14. A method of managing a telecommunications network, comprising:

detecting a request to add a network device having at least two cards to the telecommunications network;

retrieving an initial set of at least two physical identifiers from the network device, wherein at least one of said initial set of at least two physical identifiers is associated with each of said at least two cards;

converting the initial set of identifiers into a first composite value;

storing the first composite value in a storage unit accessible by a management system;

retrieving, through the management system, a current set of at least two physical identifiers from the network device, wherein at least one of said current set of at least two physical identifiers is associated with each of said at least two cards; and

authenticating an identity of the network device using at least one of said current set of at least two physical identifiers;

wherein authenticating an identity of the network device using the current set of identifiers comprises, for each retrieved identifier:

dividing the first composite value by one of the retrieved identifiers to form a division result;

converting the remaining retrieved identifiers into a second composite value;

comparing the division result to the second composite value; and

authenticating the identity of the network device if at least one of the division results matches one of the second composite values.

15. The method of claim 14 , wherein the wherein the initial set of identifiers and the current set of identifiers further comprise at least one logical identifier.

16. The method of claim 14 , wherein the physical identifiers comprise at least one Media Access Control (MAC) address.

17. The method of claim 14 , wherein the network device includes an internal bus and wherein the physical identifiers comprise at least one internal address used for communication over the internal bus.

18. The method of claim 14 , wherein each of the physical identifiers comprises a serial number for the associated card.

19. The method of claim 18 , wherein each of the physical identifiers further comprises a part number for the associated card.

20. A method of managing a telecommunications network, comprising:

authenticating an identity of a network device having at least two cards using a current set of at least two physical identifiers retrieved from the network device and a stored set of at least two physical identifiers associated with the network device, wherein at least one of said at least two physical identifiers is associated with each of said at least two cards; and

updating the stored set of identifiers when at least one but not all of the current identifiers match the stored identifiers.

21. A method of managing a telecommunications network, comprising:

connecting a management system to a network device having at least two cards using a network address assigned to the network device;

retrieving a current set of at least two physical identifiers from a network device, wherein at least one of said at least two physical identifiers is associated with each of said at least two cards; and

authenticating an identity of the network device using the current set of at least two physical identifiers.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2023
From: BANK OF AMERICA, N.A.
To: CIENA CORPORATION
Reel/Frame 065630/0232 →
PATENT SECURITY AGREEMENT Recorded Nov 8, 2019
From: CIENA CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 050969/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 30, 2019
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: CIENA CORPORATION
Reel/Frame 050938/0389 →
PATENT SECURITY AGREEMENT Recorded Jul 16, 2014
From: CIENA CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033347/0260 →
SECURITY INTEREST Recorded Jul 15, 2014
From: CIENA CORPORATION
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 033329/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2005
From: EQUIPE COMMUNICATIONS CORPORATION
To: CIENA CORPORATION
Reel/Frame 016135/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2000
From: BRANSCOMB, BRIAN; BLACK, DARRYL; PERRY, JAMES R.
To: EQUIPE COMMUNICATIONS CORPORATION
Reel/Frame 011274/0842 →
Continuity (18)
Continuation In Part 0970385600 · Nov 1, 2000
Continuation In Part 0968768700 · Oct 12, 2000
Continuation In Part 0966936400 · Sep 26, 2000
Continuation In Part 0966394700 · Sep 18, 2000
Continuation In Part 0965612300 · Sep 6, 2000
Continuation In Part 0965370000 · Aug 31, 2000
Continuation In Part 0963780000 · Aug 11, 2000
Continuation In Part 0963367500 · Aug 7, 2000
Continuation In Part 0962510100 · Jul 24, 2000
Continuation In Part 0961647700 · Jul 14, 2000
Continuation In Part 0961394000 · Jul 11, 2000
Continuation In Part 0959605500 · Jun 16, 2000
Continuation In Part 0959303400 · Jun 13, 2000
Continuation In Part 0959119300 · Jun 9, 2000
Continuation In Part 0958839800 · Jun 6, 2000
Continuation In Part 0957434100 · May 20, 2000
Continuation In Part 0957434300 · May 20, 2000
Continuation In Part 0957444000 · May 20, 2000