US2021328799A1PendingUtilityA1

Automated authentication of a new network element

Assignee: PALO ALTO NETWORKS INCPriority: May 11, 2018Filed: Jul 2, 2021Published: Oct 21, 2021
Est. expiryMay 11, 2038(~11.8 yrs left)· nominal 20-yr term from priority
H04L 9/0872H04L 9/3215H04L 9/3228H04L 9/3297H04L 9/0866H04L 9/0631H04L 63/08H04L 2463/121H04L 9/0656H04L 9/0869H04L 63/0838
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The technology presented herein enables a new network element to be authenticated to other network elements automatically. In a particular embodiment, a method provides determining a current time relative to a first time. The first time is known to the new network element and a provisioning network element. The method further provides generating first beacon data using seed data stored on the new network element and the current time and generating keying data using the first beacon data and identification information associated with the new network element. The method also provides identifying a first one-time pad (OTP) from the keying data and using the first OTP to encrypt an authentication request for transfer from the new network element to the provisioning network element.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 generating first encrypted data based, at least in part, on first data stored on a first network element and a current time;   generating second encrypted data and a first tag based, at least in part, on the first encrypted data and identification information of the first network element;   determining a first short tag from the first tag, wherein the first short tag is a subset of the first tag;   based on obtaining a second short tag, authenticating the second encrypted data based, at least in part, on the first short tag and the second short tag;   determining a one-time pad (OTP) key from the second encrypted data which has been authenticated; and   encrypting an authentication request for transfer to a second network element with the OTP key.   
     
     
         2 . The method of  claim 1 , further comprising determining the current time based, at least in part, on a reference time, wherein the current time is relative to the reference time, and wherein the reference time is maintained by the first network element and the second network element. 
     
     
         3 . The method of  claim 1  further comprising comparing the first short tag and the second short tag and determining if the first short tag and the second short tag match, wherein authenticating the second encrypted data comprises determining that the first short tag and the second short tag match. 
     
     
         4 . The method of  claim 1 , wherein obtaining the second short tag comprises obtaining the second short tag on an out-of-band channel. 
     
     
         5 . The method of  claim 1  further comprising:
 determining if the current time is indicated in an index of the second short tag; 
 based on determining that the current time is not indicated in the index of the second short tag, obtaining a third short tag; and 
 authenticating the second encrypted data based, at least in part, on the first short tag and the third short tag. 
 
     
     
         6 . The method of  claim 1 , wherein generating the first encrypted data comprises generating the first encrypted data from the first data and the current time based, at least in part, on an encryption algorithm or cryptographically secure pseudo-random function. 
     
     
         7 . The method of  claim 6 , wherein generating the first encrypted data from the first data and the current time based, at least in part, on the encryption algorithm comprises using the first data as input data for the encryption algorithm and the current time as a key or using the current time as the input data and the first data as the key. 
     
     
         8 . The method of  claim 1 , wherein generating the second encrypted data and the first tag comprises generating the second encrypted data and the first tag from the first encrypted data and the identification information based, at least in part, on an encryption algorithm or cryptographically secure pseudo-random function. 
     
     
         9 . The method of  claim 8 ,
 wherein generating the second encrypted data and the first tag from the first encrypted data and the identification information based, at least in part, on the encryption algorithm comprises using the first encrypted data as input data for the encryption algorithm and the identification information as a key or using the identification information as the input data and the first encrypted data as the key,   wherein the first tag is an output of the encryption algorithm.   
     
     
         10 . One or more non-transitory computer-readable media comprising program code to:
 generate first encrypted data based, at least in part, on first data stored on a first network element and a current time;   generate second encrypted data and a first tag based, at least in part, on the first encrypted data and identification information of the first network element;   determine a first short tag from the first tag, wherein the first short tag is a subset of the first tag;   based on obtaining a second short tag, authenticate the second encrypted data based, at least in part, on the first short tag and the second short tag;   determine a one-time pad (OTP) key from the second encrypted data which has been authenticated; and   encrypt an authentication request for transfer to a second network element with the OTP key.   
     
     
         11 . The non-transitory computer-readable media of  claim 10 , further comprising program code to determine the current time based, at least in part, on a reference time, wherein the current time is relative to the reference time, and wherein the reference time is maintained by the first network element and the second network element. 
     
     
         12 . The non-transitory computer-readable media of  claim 10  further comprising program code to compare the first short tag and the second short tag and determine whether the first short tag and the second short tag match, wherein the program code to authenticate the second encrypted data comprises program code to determine that the first short tag and the second short tag match. 
     
     
         13 . The non-transitory computer-readable media of  claim 10  further comprising program code to:
 determine whether the current time is indicated in an index of the second short tag; 
 based on a determination that the current time is not indicated in the index of the second short tag, obtain a third short tag; and 
 authenticate the second encrypted data based, at least in part, on the first short tag and the third short tag. 
 
     
     
         14 . The non-transitory computer-readable media of  claim 10 ,
 wherein the program code to generate the first encrypted data comprises program code to generate the first encrypted data based, at least in part, on using the first data as input data for an encryption algorithm and the current time as the key or using the current time as the input data and the first data as the key, and   wherein the program code to generate the second encrypted data and the first tag comprises program code to generate the second encrypted data and the first tag based, at least in part, on using the first encrypted data as input data for an encryption algorithm and the identification information as the key or using the identification information as the input data and the first encrypted data as the key.   
     
     
         15 . A first network element comprising:
 a processor; and   a computer-readable medium having instructions stored thereon that are executable by the processor to cause the first network element to,
 generate first encrypted data based, at least in part, on first data stored on the first network element and a current time; 
 generate second encrypted data and a first tag based, at least in part, on the first encrypted data and identification information of the first network element; 
 determine a first short tag from the first tag, wherein the first short tag is a subset of the first tag; 
 based on obtaining a second short tag, authenticate the second encrypted data based, at least in part, on the first short tag and the second short tag; 
 determine a one-time pad (OTP) key from the second encrypted data which has been authenticated; and 
 encrypt an authentication request for transfer to a second network element with the OTP key. 
   
     
     
         16 . The first network element of  claim 15  further comprising instructions executable by the processor to cause the first network element to determine the current time based, at least in part, on a reference time, wherein the current time is relative to the reference time, and wherein the reference time is maintained by the first network element and the second network element. 
     
     
         17 . The first network element of  claim 15  further comprising instructions executable by the processor to cause the first network element to compare the first short tag and the second short tag and determine if the first short tag and the second short tag match, wherein the instructions executable by the processor to cause the first network element to authenticate the second encrypted data comprise instructions executable by the processor to cause the first network element to determine that the first short tag and the second short tag match. 
     
     
         18 . The first network element of  claim 15  further comprising instructions executable by the processor to cause the first network element to:
 determine if the current time is indicated in an index of the second short tag; 
 based on a determination that the current time is not indicated in the index of the second short tag, obtain a third short tag; and 
 authenticate the second encrypted data based, at least in part, on the first short tag and the third short tag. 
 
     
     
         19 . The first network element of  claim 15 , wherein the instructions executable by the processor to cause the first network element to obtain the second short tag comprise instructions executable by the processor to cause the first network element to obtain the second short tag on an out-of-band channel. 
     
     
         20 . The first network element of  claim 15 ,
 wherein the instructions executable by the processor to cause the first network element to generate the first encrypted data comprise instructions executable by the processor to cause the first network element to generate the first encrypted data based, at least in part, on using the first data as input data for an encryption algorithm and the current time as a key or using the current time as the input data and the first data as the key, and   wherein the instructions executable by the processor to cause the first network element to generate the second encrypted data and the first tag comprise instructions executable by the processor to cause the first network element to generate the second encrypted data and the first tag based, at least in part, on using the first encrypted data as input data for an encryption algorithm and the identification information as a key or using the identification information as the input data and the first encrypted data as the key.

Join the waitlist — get patent alerts

Track US2021328799A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.