Router with antitheft function

By integrating a secure anti-theft password mechanism into network routers, the vulnerability to theft is mitigated, reducing unauthorized access and economic losses associated with router theft.

JP2025074030AInactive Publication Date: 2025-05-13NOKIA SOLUTIONS & NETWORKS OY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024186298
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-26
Filing Date
2024-10-23
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The ease of installation and location flexibility of small-sized network routers increases their vulnerability to theft, making router theft a significant economic issue despite existing physical security measures.

Method used

Incorporating a secure anti-theft password mechanism into the router, which includes a processor, memory for storing the password, and a computer-readable medium with instructions to determine if the input password matches the secure anti-theft password, thereby controlling access and modifications to the router's configuration.

Benefits of technology

The solution effectively reduces and prevents router theft by limiting unauthorized access and modifications, thereby reducing the economic impact of router theft and reuse of stolen routers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025074030000001_ABST
    Figure 2025074030000001_ABST
Patent Text Reader

Abstract

To reduce and / or prevent theft of a router and to restrict reuse of a stolen router.SOLUTION: According to an embodiment of the present invention, a router has at least one processor, a memory for storing at least either a safe antitheft password or a configuration file, and a computer-readable medium for storing instructions. When being carried out by the at least one processor, the instructions make the router execute a step of determining whether or not a first input password matches with the safe antitheft password, and a step of, based on a result of whether or not the first input password matches with the safe antitheft password, controlling at least either an access to or a change of the configuration file and router configuration.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] One or more exemplary embodiments relate to mitigating and / or preventing theft and / or reuse of stolen routers. [Background technology]

[0002] For ease of installation and location flexibility, it is often advantageous for a network to include a network router (hereinafter referred to as "router") having a relatively small size. Unfortunately, this advantage also increases the ease of theft of the router. Although physical mechanisms such as placing the router in a cage or in an inaccessible location are commonly used to prevent theft, it is estimated that router theft is still a multi-million dollar business. Summary of the Invention

[0003] One or more exemplary embodiments provide mechanisms to mitigate and / or prevent router theft and limit reuse of stolen routers.

[0004] In one embodiment, a router includes at least one processor, a memory that stores at least one of a secure anti-theft password or a configuration file, and a computer-readable medium (e.g., random access memory (RAM)) that stores instructions that, when executed by the at least one processor, cause the router to perform at least one of determining whether a first input password matches the secure anti-theft password and controlling access to or modification of the configuration file and the configuration of the router based on whether the first input password matches the secure anti-theft password.

[0005] In at least one embodiment, the instructions, when executed by the at least one processor, may further cause the router to perform, in response to determining that the first input password matches the anti-theft password, permitting at least one of accessing or modifying a configuration of the router and permitting at least one of accessing or modifying a configuration file.

[0006] In at least one embodiment, the instructions, when executed by the at least one processor, may further cause the router to perform, in response to determining that the first input password does not match the anti-theft password, the steps of preventing at least one of accessing or modifying the router's configuration and preventing at least one of accessing or modifying a configuration file.

[0007] In at least one embodiment, the configuration file may be an encrypted configuration file, and the instructions, when executed by the at least one processor, may further cause the router to perform the steps of obtaining the encrypted configuration file from a secure area of ​​memory, decrypting the encrypted configuration file to obtain a decrypted configuration file, and configuring the router based on the decrypted configuration file. Controlling at least one of access to or modification of the configuration file may further include preventing replacement of the encrypted configuration file with another configuration file.

[0008] In at least one embodiment, the secure anti-theft password may be encrypted and stored in a secure area of ​​memory.

[0009] In at least one embodiment, the secure area of ​​memory may include at least one of a boot read only memory (boot ROM), a boot loader memory, or a trusted platform module (TPM).

[0010] In at least one embodiment, the configuration file, when loaded onto the router, configures the router to comply with standards and protocols for the network.

[0011] In at least one embodiment, the instructions, when executed by the at least one processor, may further cause the router to perform the step of preventing entry of a second input password for a time interval in response to determining that the first input password does not match the secure anti-theft password.

[0012] In at least one embodiment, the instructions, when executed by the at least one processor, may further prompt for input of a second input password after expiration of a time interval, determine whether the second input password matches a secure anti-theft password, and control at least one of accessing or modifying a configuration file and configuring the router based on whether the second input password matches the secure anti-theft password.

[0013] In at least one embodiment, the instructions, when executed by the at least one processor, may further cause the router to perform the steps of generating a first hash using the first input password and determining whether the first input password matches the secure anti-theft password by comparing the first hash to a second hash generated using the secure anti-theft password.

[0014] In at least one embodiment, the configuration may be an encrypted configuration file encrypted using an encryption key, the encryption key being based on a secure anti-theft password, and the instructions, when executed by the at least one processor, may further cause the router to perform the steps of decrypting at least a portion of the encrypted configuration file and determining whether a result of the decryption is valid.

[0015] In one embodiment, a method of operating an anti-theft feature of a router including a processing circuit and a memory comprises determining whether a first input password matches a secure anti-theft password stored in the memory, and controlling at least one of accessing or modifying a configuration file and a configuration of the router based on whether the first input password matches the secure anti-theft password.

[0016] In at least one embodiment, controlling at least one of access to and modification of the configuration file and the router's configuration may include permitting at least one of access to or modification of the router's configuration in response to determining that the first input password matches a secure anti-theft password, and permitting at least one of access to or modification of the configuration file.

[0017] In at least one embodiment, the configuration file may be an encrypted configuration file encrypted using an encryption key, the encryption key being based on a secure anti-theft password, and the instructions, when executed by the at least one processor, may further cause the router to perform the steps of decrypting at least a portion of the encrypted configuration file and determining whether a result of the decryption is valid.

[0018] In one embodiment, a method of operating a router includes determining whether a first input password matches a secure anti-theft password stored in a memory, and controlling at least one of access to or modification of a configuration file and a configuration of the router based on whether the first input password matches the secure anti-theft password.

[0019] In at least one embodiment, controlling at least one of access to and modification of the configuration file and the router's configuration may include permitting at least one of access to or modification of the router's configuration in response to determining that the first input password matches a secure anti-theft password, and permitting at least one of access to or modification of the configuration file.

[0020] In at least one embodiment, controlling at least one of access to and modification of the configuration file and the configuration of the router may include preventing at least one of access or modification of the configuration of the router and access to and modification of the configuration file in response to determining that the first input password does not match the secure anti-theft password.

[0021] In at least one embodiment, controlling at least one of access to and modification of the configuration file and the configuration of the router includes preventing at least one of access or modification of the configuration of the router and access to and modification of the configuration file in response to determining that the first input password does not match the secure anti-theft password.

[0022] In at least one embodiment, the method may further include, in response to router boot-up, transferring the configuration file from the secure storage to an operational memory of the router, and, in response to router boot-up, decrypting the configuration file in the operational memory using a key, the key being based on at least one of the anti-theft password or a hashed version of the anti-theft password.

[0023] In at least one embodiment, the method may further include, in response to determining that the first input password does not match the secure anti-theft password, preventing input of a second input password for a time interval.

[0024] In at least one embodiment, the method may further include prompting for a second input password after expiration of the time interval, determining whether the second input password matches a secure anti-theft password, and controlling at least one of accessing and modifying the configuration file and the configuration of the router based on whether the second input password matches the anti-theft password.

[0025] In one embodiment, the non-transitory computer readable medium includes instructions that, when executed by a processor in a router, cause the router to perform at least one of the methods.

[0026] In one embodiment, means are provided for determining whether the first input password matches a secure anti-theft password stored in memory, and controlling at least one of access to or modification of a configuration file and a configuration of the router based on whether the first input password matches the secure anti-theft password.

[0027] Example embodiments will become more fully understood from the following detailed description and the accompanying drawings, in which like elements are represented by like reference numerals, which are given for purposes of illustration only and therefore are not intended to limit the disclosure. [Brief description of the drawings]

[0028] [Figure 1] FIG. 1 is a diagram illustrating an example of a router in accordance with an exemplary embodiment. [Diagram 2] FIG. 2 is a flow chart illustrating a method according to an example embodiment. [Diagram 3] FIG. 3 is a flow chart illustrating a method according to an example embodiment. [Figure 4] FIG. 4 is a flow chart illustrating an example of the operation of FIG. 3 in accordance with an exemplary embodiment. [Diagram 5] FIG. 5 is a flow chart illustrating an exemplary encryption / decryption according to an exemplary embodiment.

[0029] It should be noted that these figures are intended to illustrate the general features of methods, structures, and / or materials utilized in some exemplary embodiments, as well as to supplement the descriptions provided below. However, these figures are not to scale, may not precisely reflect the exact structure or performance characteristics of any given embodiment, and should not be construed as defining or limiting the range of values ​​or properties encompassed by the exemplary embodiments. The use of similar or identical reference numbers in the various figures is intended to indicate the presence of similar or identical elements or features. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0030] Various exemplary embodiments will now be described more fully with reference to the accompanying drawings in which some exemplary embodiments are shown. In the description and the accompanying drawings, like numerals refer to like elements throughout. Accordingly, duplicated descriptions may be omitted. In this regard, the exemplary embodiments may have different forms and should not be construed as being limited to the description set forth herein. Accordingly, the exemplary embodiments will be described below simply by referring to the drawings to describe the exemplary embodiments of the present description. Aspects of the various embodiments are specified in the claims.

[0031] Detailed exemplary embodiments are disclosed herein. However, the specific structural and functional details disclosed herein are merely representative for purposes of describing the exemplary embodiments. However, the exemplary embodiments may be realized in many alternative forms and should not be construed as being limited to only the embodiments described herein.

[0032] Thus, while exemplary embodiments are susceptible to various modifications and alternative forms, embodiments are shown by way of example in the drawings and described in detail herein. It should be understood, however, that there is no intention to limit the exemplary embodiments to the particular forms disclosed. On the contrary, the exemplary embodiments are intended to encompass all modifications, equivalents, and alternatives falling within the scope of the present disclosure. Like numbers refer to like elements throughout the description of the figures.

[0033] It will be appreciated that several of the exemplary embodiments described herein may be used in combination.

[0034] Although one or more exemplary embodiments may be described in terms of a router or other network equipment, it should be understood that one or more exemplary embodiments discussed herein may be performed by one or more processors (or processing circuits) in an applicable device. For example, according to one or more exemplary embodiments, at least one memory may include or store computer-executable instructions that, when executed by the at least one processor, cause the router to perform one or more operations described herein.

[0035] As discussed herein, "one or more" and "at least one" may be used interchangeably.

[0036] FIG. 1 illustrates an example of a router R1 in accordance with at least one exemplary embodiment.

[0037] As shown, router R1 may be a wireless and / or wired router including a memory 110, a processor 120 connected to memory 110, a communication interface 130 connected to processor 120, and one or more antennas (and / or antenna panels) 140 connected to communication interface 130. Communication interface 130 and antenna 140 may constitute a transceiver for transmitting and receiving data to and from other devices over a wireless link. Communication interface 130 may also be configured to transmit and receive data to and from other devices over a wired link (e.g., via Ethernet, optical, coaxial, and / or other connections). As will be appreciated, depending on the implementation of router R1, router R1 may include more components than those shown in FIG. 1. In at least one embodiment, router R1 may be a control processor module (CPM) router and / or a pizza box form router.

[0038] The memory 110 may be a computer-readable storage medium that generally includes a random access memory (RAM), a read-only memory (ROM), and / or a permanent mass storage device such as a disk drive. The memory 110 also stores an operating system and any other routines / modules / applications for providing the functionality of the router R1 (e.g., the method according to the exemplary embodiment) executed by the processor 120. These software components may also be loaded into the memory 110 from a separate computer-readable storage medium using a drive mechanism (not shown). Such a separate computer-readable storage medium may include a disk, a tape, a DVD / CD-ROM drive, a memory card, or other similar computer-readable storage medium (not shown). In some exemplary embodiments, the software components may be loaded into the memory 110 through one of the communication interfaces 130 rather than through a computer-readable storage medium.

[0039] As discussed in further detail below, the memory 110 may include non-volatile memory that stores encrypted and / or unencrypted configuration files (hereinafter, router configuration files). The memory 110 may include secure memory locations, such as a boot loader memory, a boot read-only memory (boot ROM), and / or a trusted platform module (TPM), that protect against unauthorized access and / or modification. As discussed in further detail below, the anti-theft features, the router configuration files, and / or the anti-theft passwords may be stored in the secure locations. In at least one exemplary embodiment, the router R1 may have anti-theft features installed by the manufacturer (e.g., if the router is Greenfield deployed) and / or the anti-theft features may be added after purchase and / or deployment (e.g., if the router is Brownfield deployed).

[0040] In at least one exemplary embodiment, the router may be configured to start in a normal operating mode until the anti-theft feature is activated so that a user can set an anti-theft password. In these cases, the user may activate the anti-theft feature after the router R1 is installed, or the anti-theft feature may be activated before the router is installed.

[0041] In at least one exemplary embodiment, the anti-theft password is set by the vendor and / or manufacturer and may be changed after or during installation of the router. Alternatively, in at least some exemplary embodiments, the anti-theft password may be a pseudo-random passcode token generated to match a corresponding one-time passcode generator provided to the user.

[0042] 1, the processor 120 may be configured to execute instructions of a computer program by performing arithmetic, logical, and input / output operations of the system. The instructions may be retrieved by the processor 120 from the memory 110.

[0043] The communication interface 130 may include components for interfacing the processor 120 with the antenna 140, or other input / output components. As will be appreciated, the communication interface 130 and the programs stored in the memory 110 for describing the dedicated functions of the router R1 may vary depending on the implementation of the router R1. In at least one exemplary embodiment, the router R1 may be configured to operate as a node in a wireless network including multiple nodes. In other examples, the router R1 may be configured to operate as a node in a wired network including multiple nodes.

[0044] 2 is a flow chart illustrating a method for entering and / or activating an anti-theft mode according to an exemplary embodiment. For illustrative purposes, the method illustrated in FIG. 2 is described with respect to the router R1 (hereinafter referred to as the router) illustrated in FIG. 1. However, the exemplary embodiment should not be limited to this example.

[0045] 2, in operation S210, the router prompts the user to set an anti-theft password. For example, in at least some embodiments, the router is configured to enter and / or activate the anti-theft mode in response to a command input to enter the anti-theft mode and / or input of the anti-theft password via a management interface, such as a command line interface (CLI), Simple Network Management Protocol (SNMP), Netconf (network configuration protocol), Netconf / YANG, Secure Shell (SSH), SSH / Telnet, etc.

[0046] For example, in some embodiments, the password is configured via a CLI knob. In at least one embodiment, a network manager and / or network service provider (NSP) can set (and / or manage) the anti-theft password. In these examples, changes to the anti-theft feature (e.g., turning the feature on / off and / or changing the password) may be restricted to administrator accounts, network manager accounts, NSP accounts, etc. Thus, users without the correct privileges may be restricted from disabling and / or changing parameters of the anti-theft mode (e.g., changing the anti-theft password).

[0047] In at least one embodiment, the router is configured to require that the anti-theft password meet (e.g., pre-configured) security requirements, such as character length requirements, alphanumeric requirements, special character requirements, etc.

[0048] In operation S220, the router secures the anti-theft password in non-volatile memory in response to entering the anti-theft mode. For example, the anti-theft password may be stored in clear text and / or as a hashed form (or value) in a secure area of ​​the non-volatile memory (e.g., in a Trusted Platform Module (TPM)). The anti-theft password may be stored in the non-volatile memory in an encrypted and / or hashed form such that the anti-theft password is not compromised if the location of the password in the memory is discovered or known. For example, the anti-theft password may be protected via an advanced encryption standard (AES) algorithm and / or a hashing algorithm (e.g., SHA-256 or similar secure hash algorithms (SHA), including PBKDF2-SHA256). Storing the anti-theft password on the system in a hashed or encrypted form ensures that the original password is not exposed even if the location of the password in the non-volatile memory or the Trusted Platform Module (TPM) is compromised and known to an eavesdropper. In at least some embodiments, the router generates and stores a hash value from the anti-theft password and stores the hash value. For example, in at least one exemplary embodiment, a hash value is generated from the anti-theft password using a key derivation function (KDF) and a suitable hash algorithm (e.g., a Secure Hash Algorithm (SHA), including SHA-256 or PBKDF2-SHA256, etc.). In at least some exemplary embodiments, generating a hash value of the password may include adding a SALT to the password to ensure that recovery of the password is difficult via a brute force or dictionary attack and / or a password recovery attack, such as a rainbow attack. In at least one embodiment, generating the hash value occurs solely in volatile memory, and the hash value is stored in a non-volatile memory location such that data related to hashing the password is not retained (or lost) upon reboot of the router.As mentioned previously and similarly above, securing the anti-theft password in hashed form (and / or encrypted form) ensures that the anti-theft password is not exposed even if the location of the anti-theft password in the non-volatile memory or the TPM is compromised and / or known, e.g., by an eavesdropper.

[0049] For example, the non-volatile memory location that stores the hash value may be a secure area of ​​memory, such as a boot loader memory, a boot ROM, and / or a TPM. As mentioned above, in at least one embodiment, the router's operating system (OS) may be prevented from accessing the secure area. The router may be configured such that the anti-theft password cannot be displayed in any show, tool, and / or other commands. If a command requires confirmation regarding the status of the anti-theft password, the anti-theft function is configured to display only the hashed form without displaying the clear text format of the anti-theft password and / or to indicate that the anti-theft password is set. In at least some embodiments, storing the anti-theft password includes encrypting the anti-theft password and / or storing a hash generated from the anti-theft password.

[0050] In step S230, the router encrypts and stores the encrypted router configuration file (hereinafter, referred to as the Router config file).

[0051] For example, in at least some embodiments, when the router enters the anti-theft mode, the Router config file is encrypted so that an unauthorized user or eavesdropper cannot modify the router configuration file or load a new configuration file onto the router. In at least one embodiment, a hash value generated from the anti-theft password is used as the key for the encryption.

[0052] As described in more detail below, when the router is in the anti-theft mode and the correct anti-theft password is entered (as when the router is operating in the normal operation mode), the user can save the router configuration as long as the router does not reboot. For example, when saving a new router configuration, the encrypted configuration file is decrypted in the volatile memory, the new configuration is appended to the Router config file, and the router configuration is stored in the non-volatile memory in encrypted form. That is, as described in more detail below, when the router is in the anti-theft mode and the router reboots, the Router config file is first decrypted (e.g., via the correct decryption key) and loaded onto the router, so that the router can provide connectivity (CLI, SNMP, etc.) to the network administrator so that the network administrator can enter the anti-theft password. Note that when the router is booting, if the router cannot correctly decrypt the configuration file, the router will not load the Router config file and the router will determine that the configuration file has been tampered with by an eavesdropper. As an example, if an eavesdropper replaces a configuration file with a new one, and since the eavesdropper does not know the correct encryption key for the configuration file, the new configuration file will be in plain text or encrypted via the wrong key, and therefore the loading of the configuration file will fail as it will not be correctly decrypted by the anti-theft encryption key set by the router owner.

[0053] The router configuration file may be stored with or separately from the anti-theft password hash value. In at least one embodiment, the Router config file may be, for example, a config file that enables the router to operate as part of a network and may include, for example, config files for Simple Network Management Protocol (SNMP), Common Management Information Protocol (CMIP), Common Management Information Service (CMIS), etc.

[0054] Thus, while in the anti-theft mode, the anti-theft functions are executed at least every time the router is booted, thereby preventing the router from replacing and / or modifying the Router config file until after successful verification (i.e., the correct anti-theft password is entered). More specifically, while in the anti-theft mode, the anti-theft functions are executed every time the router is booted, e.g., after a power off, a hard reboot, a soft reboot, etc.

[0055] As described in more detail below, the anti-theft password may be used by the router to verify that a user is authorized to use the router, that the router is authorized to access the local network, that the router has not been stolen, etc.

[0056] 3 is a flow chart illustrating a method for operating a router in an anti-theft mode according to an exemplary embodiment. For illustrative purposes, the method illustrated in FIG. 3 will be described with respect to the router R1 (hereinafter referred to as the router) illustrated in FIG. 1. However, the embodiment should not be limited to this example.

[0057] Referring to FIG. 3, in operation S300, the router is booted. During boot-up, the router retrieves boot-up instructions from memory and stores the boot-up instructions in an operational memory of the processing circuitry, such as a static random access memory (SRAM) and / or a dynamic RAM (DRAM). At this time, the router may retrieve and decode the Router config file and store the decoded Router config file in the operational memory. In at least one embodiment, the decryption of the Router config file may be performed entirely within the operational memory. For example, in at least some embodiments, the operational memory may be a volatile memory such that any data associated with the decryption of the Router config file is automatically lost during reboot.

[0058] For example, an encrypted Router config file may be decrypted and loaded into the router's operating memory in operation S300. In at least one embodiment, when the router is in anti-theft mode, the Router config file is loaded only if the decryption and verification is correct. If the router determines that the Router config file has been tampered with, the router will not execute the configuration file. The anti-theft feature further prevents unauthorized users from entering the router's configuration menu and / or causes the router to repeatedly reboot. Thus, the router is rendered inoperable because the configuration file is not being executed.

[0059] Additionally, in at least one embodiment, the encrypted Router config file may be referred to as a "start-up" configuration file, and the Router config file stored in the operational memory may be referred to as a "running" configuration file. In at least one embodiment, the Router config file may be executed by the router without password authentication, allowing the router to connect to a network corresponding to the Router config file, and allowing the user to remotely enter an anti-theft password. However, the anti-theft function prevents modification or replacement of the running configuration file and the startup configuration file. In these cases, since the startup configuration file is prevented from being modified or replaced, if conditions such as the router's location or network change, the router cannot update the running configuration file to compensate for the changes, and the router cannot execute the Router config file normally under the changed conditions, becoming inoperable under the changed conditions.

[0060] In operation S310, the router determines whether the anti-theft mode is active. For example, the router may determine that the anti-theft mode is active based on boot-up instructions that include instructions to perform the operations of the anti-theft mode.

[0061] If the router determines that the anti-theft mode is active, then in operation S320 the router prompts the user to enter an anti-theft password secured, for example, according to the method shown in Figure 2. The user may enter the password using an input device such as a keypad, keyboard, touchpad, or the like.

[0062] In operation S330, the router determines whether the input password matches the anti-theft password by comparing the password input by the user (hereinafter, the input password) with the anti-theft password. In one example, the comparison may be a simple comparison of a hash value generated based on the input password and the anti-theft password.

[0063] If the router determines that the entered password matches the anti-theft password, then in operation S340, the anti-theft function allows access and modification of the Router config file and / or allows the user to configure the router via a management interface (e.g., CLI, SNMP, Netconf, Netconf / YANG, SSH, SSH / Telnet, etc.). Thus, in at least some embodiments, configuration (required for normal operation of the router, but not for the anti-theft function and router boot-up) may also be permitted.

[0064] In at least some embodiments, the user may be further prompted to enter user authentication information. For example, the user may be prompted to enter user credentials before or after operations S310 and / or S340. In at least one example, the user credentials may include a user identification (ID) and a user password. The entered user ID and user password may be compared to a stored user ID and user password, and if the entered user ID and user password match the stored user ID and user password, the router may be configured to further load the settings and / or accounts of the user that matches the user ID. Alternatively, in at least one embodiment, if the entered user ID and / or user password do not match the stored user ID and / or user password, the router may operate normally, e.g., be allowed to modify / update the startup configuration file (e.g., the Router config file stored in memory 110) and / or the running Router config file (e.g., once decrypted), but may prevent the user from modifying the router's settings. For example, in these cases, the anti-theft mode cannot be deactivated and / or the anti-theft password cannot be changed until a valid user is confirmed.

[0065] Returning to operation S330, if the router determines that the input password does not match the anti-theft password, then in operation S350 the router does not allow (prevents) access and / or modification of the router configuration and / or the Router config file and / or any other configuration of the router. By preventing access and / or modification of the configuration and the Router config file until after confirmation that the input password matches the anti-theft password, the router is prevented from complying with standards and protocols required by changes to the network. Thus, if the router is moved, for example, to a new network, the router is rendered inoperable or useless as a router until an input password that matches the anti-theft password is entered by the user. The router is also configured to prevent uploading and execution of new Router config files and / or to implement destructive behaviors (e.g., periodic reboots, operational memory dumps, etc.) to prevent unauthorized users (e.g., eavesdroppers) from circumventing the anti-theft features, for example, using files stored and / or transferred from the compact flash and / or memory drive. This is described in more detail below.

[0066] Also, in operation S350, the router may initiate a timeout in response to determining that the entered password does not match the anti-theft password. The timeout delays in time additional attempts to enter a subsequent password when prompted (e.g., via an anti-theft feature). The delay may be a pre-configured delay or time interval set by a user or network administrator or the router manufacturer. Once the delay or time interval has expired, the process returns to operation S320 and continues as described herein.

[0067] In at least one embodiment, the router may include a counter configured to track the number of failed attempts (e.g., the number of times the input password does not match the anti-theft password). In at least some embodiments, the counter is used to pause the attempts after the number of failed attempts reaches a threshold and / or to increase the delay after each failed attempt. In at least some embodiments, the delay increases exponentially with each unsuccessful attempt, which may prevent (and / or mitigate) an unauthorized user (e.g., an eavesdropper) from determining the password via brute force (e.g., by attempting to guess the password, using a dictionary attack, and / or the like). For example, in at least one embodiment, the increase in the delay may be exponentially related to the number of unsuccessful attempts, such that the delay increases by n m where n represents a delay time unit (e.g., 2 seconds, 5 seconds, 10 seconds, 30 seconds, etc.) and m represents a count of unsuccessful attempts. However, example embodiments are not limited in this respect, and in at least some embodiments, the timeout and / or counter may be omitted.

[0068] In at least some embodiments, the counter may be reset when the router is permitted to operate in normal operation, for example, automatically after a valid password is entered.

[0069] Returning to operation S310, if the router determines that anti-theft mode has not been activated, the process proceeds to step S340, where access to the configuration file is permitted and normal operation commences as described herein.

[0070] According to an exemplary embodiment, after access to the configuration and Router config file is authorized, the router enters a normal operation mode and repeats operations S300-S350 each time the router is booted, until the anti-theft function is turned off by an authorized user (e.g., administrator, network manager, NSP, etc.) Turning off the anti-theft function is prevented unless the router is further operating in the normal operation mode.

[0071] In at least one embodiment, an authorized user may be periodically and / or automatically prompted to update the anti-theft password. For example, the period between updates may be set based on the time period between updates (e.g., six months, one year, etc.), administrative changes (e.g., adding and / or removing authorized user IDs and / or changing user passwords), etc. In at least one exemplary embodiment, an authorized user may set and / or adjust the period between updates.

[0072] 4 is a flow chart illustrating an example of operation S330 of FIG. 3 according to another embodiment of the present invention. In these examples, a hash operation is performed to determine whether the input password matches the anti-theft password.

[0073] Referring to FIG. 4, in operation S431, the router generates a first hash value using the input password or the input password and at least a portion of the Router config file.

[0074] For example, in at least one embodiment, when the router is in anti-theft mode and boots up, after verifying and decrypting the router configuration file and providing connectivity to the router, it prompts the user to enter an input password (S320) and generates a hash value based on the input password in operation S431. In at least some embodiments, generating the hash value based on the input password is also limited to operating memory such that data related to generating the hash value is lost during reboot.

[0075] In operation S432, the hash value generated based on the input password (hereinafter referred to as the second hash) is compared with the hash value generated based on the anti-theft password (hereinafter referred to as the first hash). More specifically, if the anti-theft password stored in the system and the input password are hashed by the same method, the first hash value and the second hash value should match. Therefore, if the two hash values ​​match, it means that the input password was entered correctly. If the two hash values ​​do not match, it means that the correct password was not entered. Therefore, in this example, the secure anti-theft password may be compared with the user's input password, and the router enters into a normal operation mode if the two hash values ​​match.

[0076] In other words, if the first hash matches the second hash, the method proceeds to operation S340. If the first hash does not match the second hash, the method proceeds to operation S350.

[0077] FIG. 5 is a flowchart illustrating an exemplary encryption / decryption operation according to some exemplary embodiments.

[0078] In operation S531, an encryption / decryption key is obtained. The encryption / decryption key is used together with an encryption algorithm to encrypt and / or decrypt the Router config file. As an example, the Router config file may be encrypted based on an encryption algorithm such as (AES-256). In at least one embodiment, the encryption / decryption key is derived from an anti-theft password. For example, the encryption / decryption key may be derived from the anti-theft password itself and / or from a key derivation function (KDF) of the anti-theft password.

[0079] In operation S532, the router encrypts / decrypts the Router config file using the encryption / decryption key. In at least some embodiments, a SALT or other method may be used to increase the security of the encryption. This ensures that the Router config file cannot be tampered with or replaced (e.g., by an eavesdropper), as any tampering with the file will result in a failure during decryption of the file.

[0080] In at least some example embodiments, encryption of the configuration file may be applied at operation S230 to protect the configuration file, and / or decryption of the configuration file may be applied at operation S300.

[0081] For example, in at least some embodiments, when a router attempts to boot (e.g., operation S300 of FIG. 3), the router attempts to decrypt at least a portion of the encrypted Router config file using the encryption / decryption key.

[0082] In these cases, the router determines whether the result of the decryption operation with the encryption / decryption key is valid, i.e., whether, for example, the Router config file was successfully decrypted. In at least one example, an invalid result of the decryption operation may be a non-sensing and / or non-functional output that, if executed, would not allow the router to connect to the network and / or would not allow the router to operate. In these cases, the router is configured not to execute the output of the decryption. Alternatively, after successful decryption, the router executes the output of the decryption, allowing the router to establish a connection to the original network.

[0083] More specifically, when the router is booted in anti-theft mode and loading the Router config file, if the router cannot decrypt the configuration file or cannot verify the decrypted configuration file, the router determines that the Router config file has been tampered with and does not execute or load the Router config file. If the router can decrypt and verify the Router config file, the router loads the Router config file even before the anti-theft password is entered, so that the router can provide, for example, network administrator connectivity to the router to enter the anti-theft password and put the router into normal operation mode. Because the original Router config file is specific to the original owner and network of the router, if the original configuration file is loaded after the original configuration file is stolen, the original configuration file is useless to an eavesdropper.

[0084] In this manner, a router according to one or more exemplary embodiments may be provided with an anti-theft feature that prevents configuration from being entered even if the router is stolen and the Router config file is altered and / or replaced, reducing the value and viability of the router if stolen.

[0085] Terms such as first, second, etc. may be used herein to describe various elements, but these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element can be called a second element, and similarly, a second element can be called a first element, without departing from the scope of the present disclosure. As used herein, "and / or" includes any and all combinations of one or more of the associated listed items.

[0086] When an element is referred to as being "connected" or "coupled" to another element, it can be directly connected or coupled to the other element, or there may be intervening elements. In contrast, when an element is referred to as being "directly connected" or "directly coupled" to another element, there are no intervening elements. Other words used to describe relationships between elements should be construed in a similar manner (e.g., "between," "directly between," "adjacent," "directly adjacent," etc.).

[0087] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the singular forms "a," "an," and "the" are intended to include the plural unless the context clearly dictates otherwise. Furthermore, it will be understood that the terms "comprises," "comprising," "includes," and / or "including," as used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0088] Also, in some alternative implementations, the functions / acts described may occur out of the order noted in the figures. For example, two figures shown in succession may, in fact, be executed substantially concurrently or in the reverse order, depending on the functions / acts involved.

[0089] Specific details are provided in the foregoing description to provide a thorough understanding of the exemplary embodiments. However, it will be understood by those skilled in the art that the exemplary embodiments may be practiced without these specific details. For example, systems may be shown in block diagrams to avoid obscuring the exemplary embodiments in unnecessary detail. In other instances, well-known processes, structures, and techniques may be shown without unnecessary detail to avoid obscuring the exemplary embodiments.

[0090] As described herein, the exemplary embodiments are described with reference to acts and symbolic representations of operations (e.g., in the form of flowcharts, flow diagrams, data flow diagrams, structure diagrams, block diagrams, etc.) that perform particular tasks or implement particular abstract data types and may be implemented using existing hardware, for example, in existing switches, hubs, routers, or other network elements, equipment, and / or hardware. Such existing hardware may be processing or control circuitry such as, but not limited to, one or more processors, one or more central processing units (CPUs), one or more controllers, one or more arithmetic logic units (ALUs), one or more digital signal processors (DSPs), one or more microcomputers, one or more field programmable gate arrays (FPGAs), one or more systems on chips (SoCs), one or more programmable logic units (PLUs), one or more microprocessors, one or more application specific integrated circuits (ASICs), or any other device or devices capable of responding to and executing instructions in a defined manner.

[0091] Although a flowchart may describe operations as a sequential process, many of the operations may be performed in parallel, simultaneously, or concurrently. Additionally, the order of operations may be rearranged. A process may be terminated when its operations are completed, but may have additional steps not included in the figures. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination may correspond to a return of the function to the calling function or a main function.

[0092] As disclosed herein, a "storage medium," "computer-readable storage medium," or "non-transitory computer-readable storage medium" may refer to one or more devices for storing data, including read-only memory (ROM), random access memory (RAM), magnetic RAM, core memory, magnetic disk storage media, optical storage media flash memory devices, and / or other tangible machine-readable media for storing information. A "computer-readable medium" may include, but is not limited to, portable or fixed storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data.

[0093] Further, the exemplary embodiments may be implemented by hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments for performing the necessary tasks may be stored in a machine-readable medium or computer-readable medium, such as a computer-readable storage medium. When implemented in software, one or more processors perform the necessary tasks. For example, as described above, according to one or more exemplary embodiments, at least one memory may include or store computer program code, and the at least one memory and computer program code may be configured to cause the router or other network device to perform the necessary tasks with at least one processor. Furthermore, the processor, memory, and exemplary algorithms may be encoded as computer program code and act as a means for providing or causing the execution of the operations discussed herein.

[0094] A code segment of the computer program code may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted via any suitable technique including memory sharing, message passing, token passing, network transmission, etc.

[0095] As used herein, "including" and / or "having" are defined as comprising (i.e., open language). As used herein, "cоupled" is defined as connected, although not necessarily directly and not necessarily mechanically. Terms derived from "indicating" (e.g., "indicates" and "indicatiоn") are intended to encompass all the various technologies available for communicating or referencing the indicated object / information. Some, but not all, examples of technologies available for communicating or referencing the indicated object / information include conveying the indicated object / information, conveying an identifier for the indicated object / information, conveying information used to generate the indicated object / information, conveying some part or portion of the indicated object / information, conveying some derivation of the indicated object / information, conveying some symbol representing the indicated object / information.

[0096] According to an example embodiment, switches, hubs, routers, other network elements, equipment, hardware, etc. may be (or may include) hardware, firmware, hardware executing software, or any combination thereof. Such hardware may include processing or control circuitry, such as, but not limited to, one or more processors, one or more CPUs, one or more controllers, one or more ALUs, one or more DSPs, one or more microcomputers, one or more FPGAs, one or more SoCs, one or more PLUs, one or more microprocessors, one or more ASICs, etc., or any other device or devices capable of responding to and executing instructions in a defined manner.

[0097] Benefits, other advantages, and solutions to problems have been described above with regard to specific embodiments of the invention. However, the benefits, advantages, solutions to problems, and any elements that may cause or result in such benefits, advantages, or solutions, or that may make such benefits, advantages, or solutions more significant, should not be construed as critical, necessary, or essential features or elements of any or all of the claims.

Claims

1. At least one processor; a memory for storing at least one of a secure anti-theft password or a configuration file; and a computer-readable medium storing instructions that, when executed by the at least one processor, determining whether a first input password matches the secure anti-theft password; and controlling at least one of accessing or modifying the configuration file and the configuration of the router based on whether the first input password matches the secure anti-theft password.

2. 2. The router of claim 1, wherein the instructions, when executed by the at least one processor, further cause the router to perform the steps of permitting at least one of the access or modification of the configuration of the router and permitting at least one of the access or modification of the configuration file in response to determining that the first input password matches the anti-theft password.

3. 3. The router of claim 2, wherein the instructions, when executed by the at least one processor, further cause the router to perform the steps of: preventing at least one of the access or modification of the configuration of the router; and preventing at least one of the access or modification of the configuration file in response to determining that the first input password does not match the anti-theft password.

4. 2. The router of claim 1, wherein the instructions, when executed by the at least one processor, further cause the router to perform the steps of: preventing at least one of the access or modification of the configuration of the router; and preventing at least one of the access or modification of the configuration file in response to determining that the first input password does not match the anti-theft password.

5. the configuration file is an encrypted configuration file; The instructions, when executed by the at least one processor, obtaining the encrypted configuration file from the secure area of ​​the memory; decrypting the encrypted configuration file to obtain a decrypted configuration file; and configuring the router based on the decryption configuration file.

2. The router of claim 1, wherein the controlling at least one of the access or modification of the configuration file further comprises preventing replacement of the encrypted configuration file with another configuration file.

6. 2. The router of claim 1, wherein said secure anti-theft password is encrypted and stored in a secure area of ​​said memory.

7. 7. The router of claim 6, wherein the secure area of ​​memory includes at least one of a boot read-only memory (boot-ROM), a boot loader memory, or a trusted platform module (TPM).

8. 2. The router of claim 1, wherein the configuration file, when loaded onto the router, configures the router to comply with standards and protocols for a network.

9. The instructions, when executed by the at least one processor, 2. The router of claim 1, further causing the router to perform the step of preventing entry of a second input password for a time interval in response to determining that the first input password does not match the secure anti-theft password.

10. The instructions, when executed by the at least one processor, prompting for the second input password after expiration of the time interval; determining whether the second input password matches the secure anti-theft password; and controlling at least one of the access to or modification of the configuration file and the configuration of the router based on whether the second input password matches the secure anti-theft password.

11. The instructions, when executed by the at least one processor, generating a first hash using the first input password; 2. The router of claim 1, further comprising: determining whether the first input password matches the secure anti-theft password by comparing the first hash with a second hash generated using the secure anti-theft password.

12. the configuration file is an encrypted configuration file encrypted using an encryption key, the encryption key being based on the secure anti-theft password; The instructions, when executed by the at least one processor, decrypting at least a portion of the encrypted configuration file; 2. The router of claim 1, further comprising: determining whether a result of the decryption is valid.

13. 1. A method of operating an anti-theft feature of a router, the router including a processing circuit and a memory; determining whether a first input password matches a secure anti-theft password stored in said memory; and controlling at least one of accessing or modifying a configuration file and a configuration of the router based on whether the first input password matches the secure anti-theft password.

14. 14. The method of claim 13, wherein the step of controlling at least one of the access and modification of the configuration file and the configuration of the router includes the steps of permitting at least one of the access or modification of the configuration of the router in response to determining that the first input password matches the secure anti-theft password, and permitting at least one of the access or modification of the configuration file.

15. 15. The method of claim 14, wherein the step of controlling at least one of the access and modification of the configuration file and the configuration of the router includes the steps of: preventing at least one of the access or modification of the configuration of the router in response to determining that the first input password does not match the secure anti-theft password; and preventing the access and modification of the configuration file.

16. 14. The method of claim 13, wherein the step of controlling at least one of the access and modification of the configuration file and the configuration of the router includes the steps of: preventing at least one of the access or modification of the configuration of the router and preventing the access and modification of the configuration file in response to determining that the first input password does not match the secure anti-theft password.

17. responsive to booting of the router, transferring the configuration file from secure storage to an operational memory of the router; and in response to booting the router, decrypting the configuration file in the operational memory using a key; 14. The method of claim 13, wherein the key is based on at least one of the anti-theft password or a hashed version of the anti-theft password.

18. 14. The method of claim 13, further comprising the step of preventing entry of a second input password for a time interval in response to determining that the first input password does not match the secure anti-theft password.

19. prompting for the second input password after expiration of the time interval; determining whether the second input password matches the secure anti-theft password; 20. The method of claim 18, further comprising: controlling at least one of the access to and modification of the configuration file and the configuration of the router based on whether the second input password matches the anti-theft password.

20. 14. A non-transitory computer readable medium storing instructions that, when executed by a processor in the router, cause the router to perform the method of claim 13.

Citation Information

Patent Citations

  • Router and method for updating address conversion table

    JP2002374275A

  • Computer system and user authentication method

    JP2008181440A

  • Information processing device and control method

    JP2023059150A

  • Apparatus and method for secure router with layered encryption

    US20190354685A1

  • Electronic device, method for electronic device, computer readable medium, and apparatus

    US20220045901A1