Apparatus, system, and method for secure remote configuration of network devices

    公开(公告)号:US10397047B2

    公开(公告)日:2019-08-27

    申请号:US15898207

    申请日:2018-02-15

    Abstract: The disclosed apparatus may include an encryption device that signs information exchanged between network devices to ensure the integrity of the information. The disclosed apparatus may also include a network device communicatively coupled to the encryption device, wherein the network device (1) obtains geo-location information that identifies the location of the network device, (2) directs the encryption device to sign the geo-location information to ensure the integrity of the geo-location information, (3) provides the signed geo-location information to a remote management system that manages the configuration of the network device based at least in part on the geo-location information, and (4) receives a configuration profile that modifies the configuration of the network device to account for the current location of the network device from the remote management system. Various other apparatuses, systems, and methods are also disclosed.

    Apparatus, system, and method for detecting device tampering

    公开(公告)号:US09893882B1

    公开(公告)日:2018-02-13

    申请号:US14569494

    申请日:2014-12-12

    Abstract: The disclosed apparatus may include a storage device that stores an asymmetric key pair including a public encryption key and a private encryption key assigned to a computing device. This apparatus may also include at least one processing unit communicatively coupled to the storage device. The processing unit may encrypt, via one key within the asymmetric key pair, a copy of identification information that identifies the computing device. The processing unit may then maintain the encrypted copy of the identification information and an unencrypted copy of the identification information in connection with the computing device. Next, the processing unit may detect evidence of device tampering in connection with the computing device by (1) decrypting, via another key within the asymmetric key pair, the encrypted copy of the identification information and (2) determining that the decrypted copy of the identification information differs from the unencrypted copy of the identification information.

    System and method for authorizing usage of network devices

    公开(公告)号:US09647841B1

    公开(公告)日:2017-05-09

    申请号:US14871228

    申请日:2015-09-30

    Abstract: The disclosed system may include (1) a detection module, stored in memory, that detects that a user is attempting to operate a network peripheral device configured for connecting into a base network device, at least one of the network peripheral device and the base network device including a trusted platform module that further includes an endorsement key that identifies the trusted platform module, (2) an obtaining module, stored in memory, that obtains a digitally signed indication that the user is authorized by a vendor to operate the network peripheral device, (3) an enablement module, stored in memory, that enables the user to operate the network peripheral device based on obtaining the digitally signed indication that the user is authorized by the vendor to operate the network peripheral device, and (4) at least one physical processor configured to execute these modules. Various other systems and methods are also disclosed.

    APPARATUS AND METHOD FOR AUTHENTICATING NETWORK DEVICES
    8.
    发明申请
    APPARATUS AND METHOD FOR AUTHENTICATING NETWORK DEVICES 有权
    用于认证网络设备的装置和方法

    公开(公告)号:US20160286392A1

    公开(公告)日:2016-09-29

    申请号:US14668834

    申请日:2015-03-25

    Abstract: The disclosed apparatus may include (1) a reply-reception module, stored in memory, that receives, from a satellite device, an authentication reply that includes an original authentication message digitally signed by the aggregation device using a private key of the aggregation device and that is digitally signed by the satellite device using a private key of the satellite device, (2) a forwarding module, stored in memory, that forwards the authentication reply to a network management server, (3) a validation-reception module, stored in memory, that receives, from the network management server in response to forwarding the authentication reply, a validation message, and (4) an authentication module, stored in memory, that authenticates the satellite device based at least in part on receiving the validation message. Various other apparatuses, systems, and methods are also disclosed.

    Abstract translation: 所公开的装置可以包括:(1)存储在存储器中的应答接收模块,其从卫星设备接收包括由聚合设备使用聚合设备的私钥进行数字签名的原始认证消息的认证回复,以及 由卫星设备使用卫星设备的私钥进行数字签名,(2)存储在存储器中的转发模块,其将认证回复转发给网络管理服务器,(3)验证接收模块,存储在 存储器,其从网络管理服务器接收响应于转发认证答复的验证消息,以及(4)存储在存储器中的至少部分地基于接收验证消息来认证卫星设备的认证模块。 还公开了各种其它装置,系统和方法。

    Apparatus, system, and method for protecting against denial of service attacks using one-time cookies

    公开(公告)号:US10250634B2

    公开(公告)日:2019-04-02

    申请号:US15349157

    申请日:2016-11-11

    Abstract: The disclosed apparatus may include (1) a storage device that stores a set of cookies that facilitate authenticating packets received from a node within a network and (2) a processing unit communicatively coupled to the storage device, wherein the processing unit (A) receives at least one packet from the node, (B) identifies a cookie included in the packet received from the node, (C) searches the set of cookies stored in the storage device for the cookie included in the packet received from the node, (D) identifies, during the search of the set of cookies, the cookie included in the packet and (E) protects against a DoS attack by authenticating the legitimacy of the packet based at least in part on the cookie included in the packet being identified in the set of cookies stored in the storage device. Various other apparatuses, systems, and methods are also disclosed.

Patent Agency Ranking