Claims
- 1. A network device comprising:
an interface configured to communicate with a network; a processor connected to the interface; a storage device connected to the processor; and a secure identifier stored on the storage device; wherein the processor is configured to read the secure identifier from the storage device and provide the secure identifier to the interface.
- 2. The network device of claim 1, wherein the storage device is a first storage device, the network device further comprising:
a second storage device connected to the processor, the second storage device configured to store an initial configuration address; wherein the processor is configured to initiate contact with the initial configuration address to obtain configuration instructions.
- 3. The network device of claim 2, wherein the processor is configured to communicate the secure identifier to the initial configuration address.
- 4. The network device of claim 3, wherein the initial configuration address is an address associated with a network management unit.
- 5. The network device of claim 1, further comprising:
an encryption device connected to the interface, the encryption device configured to generate the secure identifier.
- 6. The network device of claim 1, wherein the storage device is configured to store a key for decrypting an encrypted configuration instruction.
- 7. The network device of claim 6, wherein the key comprises a private key.
- 8. The network device of claim 1, wherein the secure identifier comprises a digital certificate.
- 9. The network device of claim 1, further comprising:
a decryption device configured to decrypt a configuration instruction received from a network management unit.
- 10. The network device of claim 1, wherein the network management unit comprises:
a network manager unit.
- 11. The network device of claim 5, wherein the processor and the storage device are included in a secure microcontroller.
- 12. A method for initializing a network device, the method comprising the steps of:
retrieving an initial communication address from a local memory of the network device; transmitting a secure identifier to the initial communications address, the secure identifier identifying the network device; verifying the authenticity of the secure identifier; retrieving a configuration record from a configuration record repository, the retrieved configuration record being associated with the network device that corresponds to the secure identifier; receiving at least an indication of the configuration record at the network device; and installing the at least an indication of the configuration record at the network device.
- 13. The method of claim 12, further comprising the step of:
loading the network device with the initial communications address.
- 14. The method of claim 12, further comprising:
loading the network device with the secure identifier.
- 15. The method of claim 12, further comprising the step of:
reading a key stored on the network device; and generating the secure identifier using the record key.
- 16. The method of claim 12 wherein the secure identifier comprises:
a digital certificate.
- 17. The method of claim 12 wherein the step of verifying comprises the step of:
retrieving a key from the configuration record that was retrieved from the configuration record repository, wherein the key is associated with the network device.
- 18. The method of claim 12, wherein the secure identifier is a first secure identifier, the method further comprising the steps of:
receiving a second secure identifier from a network management unit; verifying the authenticity of the received second secure identifier; and responsive to verifying the authenticity of the second secure identifier, accepting configuration instructions for installation.
RELATED APPLICATIONS
[0001] The following commonly owned and assigned patent applications are hereby incorporated by reference in their entirety:
[0002] patent application Ser. No. 09/730,864, Attorney Docket No. CNTW-001/00US, entitled System and Method for Configuration, Management and Monitoring of Network Resources, filed on Dec. 6, 2000;
[0003] patent application Ser. No. 09/730,680, Attorney Docket No. CNTW-002/00US, entitled System and Method for Redirecting Data Generated by Network Devices, filed on Dec. 6, 2000;
[0004] patent application Ser. No. 09/730,863, Attorney Docket No. CNTW-003/00US, entitled Event Manager for Network Operating System, filed on Dec. 6, 2000;
[0005] patent application Ser. No. 09/730,671, Attorney Docket No. CNTW-004/00US, entitled Dynamic Configuration of Network Devices to Enable Data Transfers, filed on Dec. 6, 2000;
[0006] patent application Ser. No. 09/730,682, Attorney Docket No. CNTW-006/00US, entitled Network Operating System Data Directory, filed on Dec. 6, 2000.
[0007] patent application Ser. No. 09/799,579, Attorney Docket No. CNTW-006/01US, entitled Global GUI Interface for Network OS, filed on Jul. 2, 2001;
[0008] patent application Ser. No. 09/942,834, Attorney Docket No. CNTW-007/00US, entitled System and Method for Generating a Configuration Schema, filed on Aug. 29, 2001;
[0009] patent application Ser. No. 09/942,833, Attorney Docket No. CNTW-008/00US, entitled System and Method for Modeling a Network Device's Configuration, filed on Aug. 29, 2001; and
[0010] patent application Ser. No. 09/991,764, Attorney Docket No. CNTW-011/00US, entitled System and Method for Generating a Representation of a Configuration Schema, filed on Nov. 26, 2001.