Secure configuration of a headless networking device

USRE49012E · US · E1

Patent metadata
FieldValue
Publication numberUS-RE49012-E
Application numberUS-201916443547-A
CountryUS
Kind codeE1
Filing dateJun 17, 2019
Priority dateMar 1, 2013
Publication dateApr 5, 2022
Grant dateApr 5, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The secure configuration of a headless networking device is described. A label associated with the headless networking device is scanned and a public key is determined. scanning a label associated with a networking device. A configuration process is initiated for the networking device using the public key associated with the networking device that was determined based on the scanned label.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer-readable medium comprising instructions which, when executed by one or more hardware processors, cause the one or more hardware processors to: determine a public key associated with a networking device using an external label associated with the networking device; authenticate the networking device based upon a determination as to whether the networking device possesses a private key analog to the public key associated with the networking device; and initiate a configuration process for the networking device after the networking device is authenticated, wherein the configuration process facilitates access by the networking device to a secure network, and wherein the configuration process includes sending a domain parameter to provide configuration information for the configuration process and an address for a domain name server to the networking device. 2. The non-transitory computer-readable medium of claim 1 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to: generate a shared secret using the public key associated with the networking device and send the shared secret to the networking device; encrypt a first information with the shared secret and send the encrypted first information to the networking device; and receive a second information from the networking device that indicates that the networking device possesses the private key analog to the public key associated with the networking device. 3. The non-transitory computer-readable medium of claim 2 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to integrity protect the encrypted first information prior to sending the encrypted first information to the networking device. 4. The non-transitory computer-readable medium of claim 2 , wherein the instructions are further to cause the one or more hardware processors to send assurance to the networking device before initiating the configuration process by encrypting a third information with the shared secret and sending the encrypted third information to the networking device. 5. The non-transitory computer-readable medium of claim 2 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to receive an indication from the networking device possessing the shared secret that the networking device possesses the private key analog to the public key associated with the network device. 6. The non-transitory computer-readable medium of claim 2 , wherein to generate the shared secret, the instructions are further to cause the one or more hardware processors to perform a static ephemeral Diffie-Hellman key exchange. 7. The non-transitory computer-readable medium of claim 2 , wherein to encrypt the first information, the instructions are further to cause the one or more hardware processors to wrap a first nonce in the shared secret. 8. The non-transitory computer-readable medium of claim 7 , wherein to receive the second information, the instructions are further to cause the one or more hardware processors to receive two encrypted nonces and wherein to determine that the networking device possesses the shared secret, the instructions are further to cause the one or more hardware processors to determine whether the encryption of the two nonces is valid. 9. The non-transitory computer-readable medium of claim 8 , wherein to receive the second information, the instructions are further to cause the one or more hardware processors to receive two nonces encrypted with the shared secret from the networking device, and decrypt and verify the two nonces. 10. An apparatus comprising: one or more hardware processors; a memory on which is stored instructions that are to cause the one or more hardware processors to: determine a public key associated with a networking device using an external label associated with the networking device; authenticate the networking device based upon a determination as to whether the networking device possesses a private key analog to the public key associated with the networking device; and initiate a configuration process for the networking device after the networking device has been authenticated, wherein the configuration process facilitates access by the networking device to a secure network, and wherein the configuration process includes sending a domain parameter to provide configuration information for the configuration process and an address for a domain name server to the networking device. 11. The apparatus of claim 10 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to: generate a shared secret using the public key associated with the networking device and send the shared secret to the networking device; encrypt a first information with the shared secret and send the encrypted first information to the networking device; and receive a second information from the networking device that indicates that the networking device possesses the private key analog to the public key associated with the networking device. 12. The apparatus of claim 11 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to integrity protect the encrypted first information prior to sending the encrypted first information to the networking device. 13. The apparatus of claim 11 , wherein the instructions are further to cause the one or more hardware processors to send assurance to the networking device before initiating the configuration process by encrypting a third information with the shared secret and sending the encrypted third information to the networking device wherein the networking device does not accept configuration unless the networking device can decrypt the third information using the shared secret. 14. The apparatus of claim 11 , wherein to authenticate the networking device, the instructions are further to cause the one or more hardware processors to receive an indication from the networking device possessing the shared secret that the networking device possesses the private key analog to the public key determined associated with the networking device. 15. The apparatus of claim 11 , wherein to generate the a shared secret, the instructions are further to cause the one or more hardware processors to perform a static ephemeral Diffie-Hellman key exchange. 16. The apparatus of claim 11 , wherein to encrypt the first information, the instructions are further to cause the one or more hardware processors to wrap a first nonce in the shared secret. 17. The apparatus of claim 16 , wherein to receive the second information, the instructions are further to cause the one or more hardware processors to receive two encrypted nonces and wherein to determine that the networking device possesses the shared secret, the instructions are further to cause the one or more hardware processors to determine whether the encryption of the two nonces is valid. 18. The apparatus of claim 17 , wherein to receive the second information, the instructions are further to cause the one or more hardware processors to receive two nonces encrypted with the shared secret from the networking device, and decrypt and verify the two nonces. 19. An apparatus comprising: an external key label associated with a public key; an internal secure key storage to store a pri

Assignees

Inventors

Classifications

  • G09C5/00Primary

    Ciphering apparatus or methods not provided for in the preceding groups, e.g. involving the concealment or deformation of graphic data such as designs, written or printed messages · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • involving Diffie-Hellman or related key agreement protocols · CPC title

  • Graphical identity · CPC title

  • using different networks or channels, e.g. using out of band channels (cryptographic mechanisms or cryptographic arrangements for key distribution involving distinctive intermediate devices or communication paths H04L9/0827; cryptographic mechanisms or cryptographic arrangements for authentication using a plurality of channels H04L9/3215) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent USRE49012E cover?
The secure configuration of a headless networking device is described. A label associated with the headless networking device is scanned and a public key is determined. scanning a label associated with a networking device. A configuration process is initiated for the networking device using the public key associated with the networking device that was determined based on the scanned label.
Who is the assignee on this patent?
Hewlett Packard Entpr Dev Lp
What technology area does this patent fall under?
Primary CPC classification G09C5/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 05 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (E1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).