US2015365413A1PendingUtilityA1
Secure Configuration of Authentication Servers
Est. expiryMay 19, 2028(~1.8 yrs left)· nominal 20-yr term from priority
Inventors:Larry Dean Hofer
H04L 63/20H04L 63/083G06F 17/30876G06F 17/30312H04L 63/0884G06F 21/602G06F 16/955G06F 16/22H04L 41/0856H04L 63/08H04L 63/0428
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Embodiments of the invention are directed to automatically populating a database of names and secrets in an authentication server by sending one or more lists of one or more names and secrets by a network management software to an authentication server. Furthermore, some embodiments provide that the lists being sent are encrypted and/or embedded in otherwise inconspicuous files.
Claims
exact text as granted — not AI-modified1 . A method for configuring a management database comprising:
assigning a plurality of secrets to a plurality of nodes of a network; generating a data structure in each node of the plurality of nodes, the data structure comprising the assigned secrets; securing the data structure in each node of the plurality of nodes using a password generated according a key agreement protocol; and storing each generated password in the management database.
2 . The method of claim 1 , further comprising integrating the data structure into an authentication server database.
3 . The method of claim 1 , wherein securing the data structure comprises encrypting the data structure.
4 . The method of claim 1 , wherein encrypting the data structure comprises encrypting the data structure with a password used for communications with the authentication server or a derivation thereof.
5 . The method of claim 1 , wherein securing the data structure comprises embedding the data structure within a second data structure through the use of steganography.
6 . The method of claim 1 , further comprising generating the plurality of secrets.
7 . The method of claim 1 , wherein the assigning, generating, securing and storing are performed by an authentication management application executed at a computer that is distinct from an authentication server.
8 . The method of claim 1 , further comprising associating each secret with a unique name of a node the secret is assigned to and saving the associated names in the data structure.
9 . The method of claim 1 , wherein the network comprises a storage area network.
10 . The method of claim 9 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.
11 . The method of claim 1 , further comprising:
obtaining the assigned secrets from the data structure by an authentication server; and using the assigned secrets by the authentication server to perform authentication for the plurality of nodes.
12 - 15 . (canceled)
16 . A device comprising a processor and a memory, the memory comprising a plurality of instructions executable at the processor and configured to cause the processor to:
assign a plurality of secrets to a plurality of nodes of a network; generate a data structure in each node of the plurality of nodes, the data structure comprising the assigned secrets; secure the data structure in each node of the plurality of nodes using a password generated according a key agreement protocol; and store each generated password in a management database.
17 . The device of claim 16 , wherein the instructions are further configured to cause the processor to generate or otherwise establish the plurality of secrets.
18 . The device of claim 16 , wherein the instructions are part of an authentication management application, and the device is distinct from an authentication server.
19 . The device of claim 16 , wherein the instructions are further configured to cause the processor to associate each secret with a unique name of a node the secret is assigned to and save the associated names in the data structure.
20 . The device of claim 16 , wherein the network comprises a storage area network.
21 . The device of claim 20 , wherein the storage area network is a network selected from the group consisting of a Fibre Channel network, an iSCSI network and an FCoE network.
22 - 25 . (canceled)
26 . A network device comprising:
a memory comprising a management database; and a hardware processor operable to:
generate a password according to a key agreement protocol;
store the password in the management database; and
assign a plurality of secrets to a network node, the plurality of secrets comprising the password, one or more of the plurality of secrets being stored in a data structure in each node, the data structure being secured by the password.
27 . The network device of claim 26 , wherein the data structure is encrypted by with the password.
28 . The network device of claim 26 , wherein the data structure is embedded through the use of steganography.Join the waitlist — get patent alerts
Track US2015365413A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.