Network security through configuration servers in the fabric environment
Abstract
A network configuration device or entity has control of defined management and security functions in the network, or in many embodiments, in a Fibre Channel fabric. The network configuration device may control many functions. Foremost, it may control the recognition, operation and succession procedure for network configuration entities. It may also control user configurable options for the network, rules for interaction between other entities in the network, rules governing management-level access to the network, and rules governing management-level access to individual devices in the network. In addition, the network configuration entity may exploit policy sets to implement its control.
Claims
exact text as granted — not AI-modified1 - 38 . (canceled)
39 . A method of securing a Fibre Channel network comprising the steps of:
defining a set of management and security functions; designating a single entity to be responsible for implementation of said defined set of functions, wherein responsibility for implementation comprises performing network-wide management requests, and initiating password changes; and limiting logical access to the network to devices designated by said single entity.
40 . The method of claim 39 further comprising the steps of:
Providing a list of devices eligible to become said single entity.
41 . The method of claim 40 wherein said single entity is the first listed device.
42 . The method of claim 41 further comprising the step of:
upon the unavailability of said single entity, using the second listed entity as a replacement for said single entity.
43 . The method of claim 41 further comprising the step of:
upon the unavailability of said second listed entity, using the third listed entity as a replacement for said single entity.
44 . The method of claim 40 further comprising the steps of:
upon the unavailability of said single entity, stopping all substantive communication in the network; re-starting substantive communication upon the availability of said single entity or a replacement for said single entity.
45 . The method of claim 40 further comprising the step of:
upon the unavailability of said single entity, choosing any capable device in the network as a replacement for said single entity.
46 . The method of claim 40 further comprising the step of:
upon the unavailability of said single entity, allowing no management or security function changes in the network until either (i) said single entity or a replacement for said single entity becomes available, or (ii) a predefined operator override occurs.
47 . The method of claim 40 further comprising the steps of:
physically connecting a new device to the network; first, downloading management information associated with said defined set of management and security functions from said single entity to said new device; second, allowing said new device to logically connect to the network.
48 . The method of claim 47 where in the step of allowing said new device to logically connect to the network, comprises the sub-step of distributing said management information to all other entities in the network.
49 . The method of claim 47 wherein said management information comprises one or more policy sets.
50 - 54 . (canceled)Join the waitlist — get patent alerts
Track US2006080727A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.