IP Library Granted Patent US 10,069,802
Granted Patent B2
US 10,069,802 · App. 14/183,180 · Granted Sep 4, 2018

Method for securely configuring customer premise equipment

Inventors: Simon Paul Parry (Manuden, GB); James Alexander Ivens Holtom (Writtle, GB)
Assignee: Ciena Corporation
H04L63/0428H04L61/2503H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,069,802
App. No.
14/183,180
Granted
Sep 4, 2018
Kind
B2
Abstract

A method for securely configuring a customer premise equipment in a network. The network including a configuration server, a DHCP server, and the customer premise equipment. The method includes receiving a request from the customer premise equipment for leasing an Internet Protocol (IP) address to the customer premise equipment. The method further includes embedding at least a portion of a Media Access Control (MAC) address of the customer premise equipment into the IP address leased to the customer premise equipment. The method includes leasing the IP address to the customer premise equipment. Further, the method enables authentication of customer premise equipment, before providing configuration to the customer premise equipment. The method includes use of characteristic attributes of the customer premise equipment to generate cryptographic keys for secure connection. Moreover, the method includes establishing a secure connection between the configuration server and the customer premise equipment for transfer of a configuration file and a set of encryption keys. The configuration file and the set of encryption keys are used to securely configure the customer premise equipment.

Claims (34)

1. A method for securely configuring a customer premise equipment in a network, the network including a configuration server, a dynamic host configuration protocol (DHCP) server, and the customer premise equipment, the method comprising:

receiving a request at the DHCP server from the customer premise equipment for leasing an Internet Protocol (IP) address to the customer premise equipment;

embedding at least a portion of a Media Access Control (MAC) address of the customer premise equipment into the IP address leased to the customer premise equipment;

leasing the IP address to the customer premise equipment;

establishing a secure connection between the configuration server and the customer premise equipment for transfer of a configuration file using a permanent set of encryption keys, wherein the configuration server obtains the at least a portion of the MAC address by reading directly from the IP address to establish the secure connection irrespective of how the customer premise equipment and the configuration server are connected to one another, and wherein the configuration server and the customer premise equipment each independently generate the permanent set of encryption keys based on the at least a portion of the MAC address as a seed value and a salt value added thereto based on a service provider associated with the customer premises equipment before any communication there between; and

securely configuring the customer premise equipment using the configuration file and the permanent set of encryption keys.

2. The method as recited in claim 1 further comprising notifying the configuration server regarding the IP address leased to the customer premise equipment.

3. The method as recited in claim 1 , wherein establishment of a secure connection between the configuration server and the customer premise equipment is triggered by the customer premise equipment.

4. The method as recited in claim 1 , wherein embedding at least a portion of the MAC address of the customer premise equipment into the IP address leased to the customer premise equipment and leasing the IP address to the customer premise equipment is performed by the DHCP server.

5. The method as recited in claim 1 , wherein in case the customer premise equipment supports Internet Protocol version 4 (IPv4), then last 24-bits of the 48-bits MAC address are embedded in the IP address leased to the customer premise equipment.

6. The method as recited in claim 1 , wherein in case the customer premise equipment supports Internet Protocol version 6 (IPv6), then at least a portion of the MAC address is embedded in the IP address leased to the customer premise equipment.

7. The method as recited in claim 1 , wherein the secure connection between the configuration server and the customer premise equipment is a Secure Shell (SSH) tunnel.

8. A method for establishing a secure connection between a configuration server and a customer premise equipment for securely configuring the customer premise equipment in a network, the method comprising:

receiving a communication from the customer premise equipment containing the identity of the customer premise equipment, wherein the IP address leased to the customer premise equipment is embedded with at least a portion of a Media Access Control (MAC) address of the customer premise equipment;

identifying the MAC address of the customer premise equipment from the IP address leased to the customer premise equipment; receiving a request for transferring a configuration file to the customer premise equipment;

generating a pair of public and private keys for securely transferring the configuration file to the customer premise equipment, wherein the pair of public and private keys is generated independently at each of the customer premise equipment and the configuration server based on the at least a portion of the MAC address as a seed value and a salt value added thereto based on a service provider associated with the customer premise equipment before any communication there between;

establishing the secure connection between the configuration server and the customer premise equipment for securely transferring the configuration file to the customer premise equipment, wherein the configuration server obtains the at least a portion of the MAC address by reading directly from the IP address to establish the secure connection irrespective of how the customer premise equipment and the configuration server are connected to one another; and

configuring the customer premise equipment using the configuration file.

9. The method as recited in claim 8 , wherein the request for transferring the configuration file to the customer premise equipment is triggered by the customer premise equipment.

10. The method as recited in claim 8 , wherein in case the customer premise equipment supports Internet Protocol version 4 (IPv4), then last 24-bits of the 48-bits MAC address are embedded in the IP address leased to the customer premise equipment.

11. The method as recited in claim 8 , wherein in case the customer premise equipment supports Internet Protocol version 6 (IPv6), then the complete MAC address is embedded in the IP address leased to the customer premise equipment.

12. The method as recited in claim 8 , wherein the secure connection between the configuration server and the customer premise equipment is a Secure Shell (SSH) tunnel.

13. The method as recited in claim 8 , wherein the pair of public and private keys is generated by using a pseudo-random prime generator algorithm.

14. The method as recited in claim 8 , wherein the pair of public and private keys is generated by using at least a portion of the MAC address or some characteristic of the customer premise equipment as a seed.

15. A non-transitory computer-readable medium comprising code for causing a computer to:

receive a request at a dynamic host configuration protocol (DHCP) server from a customer premise equipment for leasing an Internet Protocol (IP) address to the customer premise equipment;

embed at least a portion of a Media Access Control (MAC) address of the customer premise equipment into the IP address leased to the customer premise equipment;

lease the IP address to the customer premise equipment;

establish a secure connection between a configuration server and the customer premise equipment for transfer of a configuration file using a permanent set of encryption keys, wherein the configuration server obtains the at least a portion of the MAC address directly from the IP address to establish the secure connection irrespective of how the customer premise equipment and the configuration server are connected to one another, and wherein the configuration server and the customer premise equipment each independently generate the permanent set of encryption keys based on the at least a portion of the MAC address as a seed value and a salt value added thereto based on a service provider associated with the customer premises equipment before any communication therebetween; and

securely configuring the customer premise equipment using the configuration file and the permanent set of encryption keys.

16. The non-transitory computer-readable medium of claim 15 , wherein the code further causes notification of the configuration server regarding the IP address leased to the customer premise equipment.

17. The non-transitory computer-readable medium of claim 15 , wherein the code further causes establishment of a secure connection between the configuration server and the customer premise equipment is triggered by the customer premise equipment.

18. The non-transitory computer-readable medium of claim 15 , wherein the code further causes embedding at least a portion of the MAC address of the customer premise equipment into the IP address leased to the customer premise equipment and leasing the IP address to the customer premise equipment is performed by the DHCP server.

19. The non-transitory computer-readable medium of claim 15 , wherein the code further causes a last 24-bits of a 48-bits MAC address to be embedded in the IP address leased to the customer premise equipment.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2023
From: BANK OF AMERICA, N.A.
To: CIENA CORPORATION
Reel/Frame 065630/0232 →
PATENT SECURITY AGREEMENT Recorded Nov 8, 2019
From: CIENA CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 050969/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 30, 2019
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: CIENA CORPORATION
Reel/Frame 050938/0389 →
PATENT SECURITY AGREEMENT Recorded Jul 16, 2014
From: CIENA CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 033347/0260 →
SECURITY INTEREST Recorded Jul 15, 2014
From: CIENA CORPORATION
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 033329/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2014
From: PARRY, SIMON PAUL; HOLTOM, JAMES ALEXANDER IVENS
To: CIENA CORPORATION
Reel/Frame 032238/0184 →
Continuity (1)
Related Publication 20150237018A1 · Aug 20, 2015
Cited By (1)
US 12,457,129