US2015365413A1PendingUtilityA1

Secure Configuration of Authentication Servers

Assignee: EMULEX CORPPriority: May 19, 2008Filed: Aug 26, 2015Published: Dec 17, 2015
Est. expiryMay 19, 2028(~1.8 yrs left)· nominal 20-yr term from priority
H04L 63/20H04L 63/083G06F 17/30876G06F 17/30312H04L 63/0884G06F 21/602G06F 16/955G06F 16/22H04L 41/0856H04L 63/08H04L 63/0428
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments of the invention are directed to automatically populating a database of names and secrets in an authentication server by sending one or more lists of one or more names and secrets by a network management software to an authentication server. Furthermore, some embodiments provide that the lists being sent are encrypted and/or embedded in otherwise inconspicuous files.

Claims

exact text as granted — not AI-modified
1 . A method for configuring a management database comprising:
 assigning a plurality of secrets to a plurality of nodes of a network;   generating a data structure in each node of the plurality of nodes, the data structure comprising the assigned secrets;   securing the data structure in each node of the plurality of nodes using a password generated according a key agreement protocol; and   storing each generated password in the management database.   
     
     
         2 . The method of  claim 1 , further comprising integrating the data structure into an authentication server database. 
     
     
         3 . The method of  claim 1 , wherein securing the data structure comprises encrypting the data structure. 
     
     
         4 . The method of  claim 1 , wherein encrypting the data structure comprises encrypting the data structure with a password used for communications with the authentication server or a derivation thereof. 
     
     
         5 . The method of  claim 1 , wherein securing the data structure comprises embedding the data structure within a second data structure through the use of steganography. 
     
     
         6 . The method of  claim 1 , further comprising generating the plurality of secrets. 
     
     
         7 . The method of  claim 1 , wherein the assigning, generating, securing and storing are performed by an authentication management application executed at a computer that is distinct from an authentication server. 
     
     
         8 . The method of  claim 1 , further comprising associating each secret with a unique name of a node the secret is assigned to and saving the associated names in the data structure. 
     
     
         9 . The method of  claim 1 , wherein the network comprises a storage area network. 
     
     
         10 . The method of  claim 9 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network. 
     
     
         11 . The method of  claim 1 , further comprising:
 obtaining the assigned secrets from the data structure by an authentication server; and   using the assigned secrets by the authentication server to perform authentication for the plurality of nodes.   
     
     
         12 - 15 . (canceled) 
     
     
         16 . A device comprising a processor and a memory, the memory comprising a plurality of instructions executable at the processor and configured to cause the processor to:
 assign a plurality of secrets to a plurality of nodes of a network;   generate a data structure in each node of the plurality of nodes, the data structure comprising the assigned secrets;   secure the data structure in each node of the plurality of nodes using a password generated according a key agreement protocol; and   store each generated password in a management database.   
     
     
         17 . The device of  claim 16 , wherein the instructions are further configured to cause the processor to generate or otherwise establish the plurality of secrets. 
     
     
         18 . The device of  claim 16 , wherein the instructions are part of an authentication management application, and the device is distinct from an authentication server. 
     
     
         19 . The device of  claim 16 , wherein the instructions are further configured to cause the processor to associate each secret with a unique name of a node the secret is assigned to and save the associated names in the data structure. 
     
     
         20 . The device of  claim 16 , wherein the network comprises a storage area network. 
     
     
         21 . The device of  claim 20 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network. 
     
     
         22 - 25 . (canceled) 
     
     
         26 . A network device comprising:
 a memory comprising a management database; and   a hardware processor operable to:
 generate a password according to a key agreement protocol; 
 store the password in the management database; and 
 assign a plurality of secrets to a network node, the plurality of secrets comprising the password, one or more of the plurality of secrets being stored in a data structure in each node, the data structure being secured by the password. 
   
     
     
         27 . The network device of  claim 26 , wherein the data structure is encrypted by with the password. 
     
     
         28 . The network device of  claim 26 , wherein the data structure is embedded through the use of steganography.

Join the waitlist — get patent alerts

Track US2015365413A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.