Schneider Electric : Patent Issued for Methods and Systems for Establishing Secure Authenticated Bidirectional Server Communication Using Automated Credential ReservationElectrical Contractors - Residential & CommercialUpdated on Sep 22, 2017 View more like this | Visit India, UN | Contact Rakesh Kumar |

Patent Issued for Methods and Systems for Establishing Secure Authenticated Bidirectional Server Communication Using Automated Credential Reservation (USPTO 9762578)
By a News Reporter-Staff News Editor at Computer Weekly News -- SCHNEIDER ELECTRIC IT CORPORATION (West Kingston, RI) has been issued patent number 9762578, according to news reporting originating out of Alexandria, Virginia, by VerticalNews editors.
The patent's inventors are Emerick, Gregory M. (O'Fallon, MO); Gifford, Paul J. (Somerset, MA).
This patent was filed by Schneider Electric on October 25, 2010 and was published online on September 12, 2017.
From the background information supplied by the inventors, news correspondents obtained the following quote: "The present invention relates generally to the field of secure network communications, and more particularly, to methods and systems for establishing secure authenticated bidirectional server communication using automated credential reservation.
"Data centers are widely used to house various types of electrical equipment, including computer systems and the physical infrastructure needed to support such systems, such as power supplies (e.g., uninterruptible power supplies and backup power supplies), environmental systems (e.g., air conditioning, fire suppression, etc.), physical data center security, and other monitoring devices. Companies that depend on the proper and efficient operation of their data centers use various tools to monitor and operate the physical infrastructure, including multiple monitoring systems that are coordinated to provide centralized collection and reporting of critical infrastructure events."
Supplementing the background information on this patent, VerticalNews reporters also obtained the inventors' summary information for this patent: "According to one embodiment, a method of authenticating communications includes acts of receiving, by a computer, a first set of credentials and verifying the first set of credentials by comparing the first set of credentials to a plurality of sets of credentials stored in a database. Subsequent to verifying the first set of credentials, the method further includes acts of deriving a second set of credentials, and transmitting notification of the second set of credentials to a remote computer.
"According to various embodiments, the act of verifying the first set of credentials may be performed by the remote computer. The first set of credentials may be created by a user of the computer. The first set of credentials may be created on the remote computer. The first set of credentials may include a username and password. At least one of the first set of credentials and the second set of credentials may be encrypted by the computer. The second set of credentials may be stored in a database accessible by the computer.
"In another embodiment, the method may further include an act of receiving, by the computer, contact information for the remote computer.
"In another embodiment, the method may further include an act of establishing, by the remote computer, secure communications with the computer using at least the second set of credentials.
"In yet another embodiment, the method may further comprise an act of automatically changing at least one of the first set of credentials and the second set of credentials using the at least one of the first set of credentials and the second set of credentials as a seed for calculating a new set of credentials to replace the at least one of the first set of credentials and the second set of credentials. The act of automatically changing may occur periodically. The act of automatically changing may occur in response to at least one of a user event, a system event, and a security event.
"According to another embodiment, a method of authenticating communications between a first computer and a second computer includes acts of receiving, from a user, a first set of credentials at the first computer; receiving, from the user, the first set of credentials at the second computer; calling, by the second computer, a first service operating on the first computer, the first service configured to provide verification of the first set of credentials to the second computer; responsive to receiving the verification of the first set of credentials from the second computer, deriving a second set of credentials by the second computer; and transmitting notification of the second set of credentials from the second computer to the first computer.
"In another embodiment, the method may further include an act of establishing, by the second computer, secure communications with the first computer using at least the second set of credentials.
"In another embodiment, the method may further include an act of establishing, by the first computer, secure communications with the second computer using at least the first set of credentials.
"In yet another embodiment, the method may further include an act of automatically changing at least one of the first set of credentials and the second set of credentials using the at least one of the first set of credentials and the second set of credentials as a seed for calculating a new set of credentials to replace the at least one of the first set of credentials and the second set of credentials. The act of automatically changing may occur periodically. The act of automatically changing may occur in response to at least one of a user event, a system event, and a security event.
"According to another embodiment, a data center infrastructure management system includes a network, a first server connected to the network, a plurality of data center infrastructure devices connected to the first server, the first server being configured to maintain device data related to management of the plurality of data center infrastructure devices, and a second server connected to the network and configured to verify a set of user-created credentials, to be supplied by the first server, by comparing the set of user-created credentials to a plurality of sets of user-created credentials stored in a database, the second server further configured to derive a set of server-created credentials based on the set of user-created credentials subsequent to verifying the set of user-created credentials, the second server further configured to notify the first server of the set of server-created credentials subsequent to deriving the set of server-created credentials. The first server uses the set of server-created credentials to establish secure communication with the second server for exchanging the device data with the second server.
"In another embodiment, the system may be configured to establish secure communication between the first server and a second server through the network using at least the set of used-created credentials and the set of server-created credentials.
"According to one embodiment, a data center infrastructure management system includes a plurality of central servers configured to maintain device data related to management of a plurality of data center infrastructure devices located within one or more data centers and a global server connected to the plurality of central servers through a first network. The global server is configured to receive at least a subset of the device data asynchronously from each of the plurality of central servers, and is further configured to store the at least the subset of the device data in a database, and is further configured to generate and maintain an index of the subset of the device data. The index is configured to facilitate searching of the subset of the device data in the database by the global server. The system further includes a global client connected to the global server through a second network, the global client having a user interface configured to request and receive from the global server at least one of a portion of the subset of the device data and a portion of the device data. The portion of the subset of the device data is to be located in the database using the index by the global server in response to the request, and the portion of the device data is to be received from the plurality of central servers in response to a request by the global client for data that is not in the database.
"In another embodiment, the global client may include a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the subset of the device data may includes data center asset inventory data.
"In yet another embodiment, the global server may be further configured to request the device data from the plurality of central servers in response to the request from the global client for the device data, wherein the device data is not stored in the database, and wherein the global server is further configured to provide the device data to the global client in a lightweight format subsequent to receiving the device data from the plurality of central servers. The lightweight format of the device data may be a format that is adapted for consumption by a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the global client may include a data requestor component configured to request at least one of the portion of the subset of the device data and the portion of the device data, and further configured to display the at least one of the portion of the subset of the device data and the portion of the device data.
"In another embodiment, the index may include a table of ordered records including at least one of the data, an occurrence frequency of the data, a database table name, and identification information for locating the data in the database.
"According to another embodiment, a Schneider Electric data center infrastructure management system includes a plurality of central servers configured to maintain device data related to management of a plurality of data center infrastructure devices located within one or more data centers. Each of the plurality of central servers has an asynchronous event component configured to automatically generate a first portion of the device data in response to a change in a status of at least one of the plurality of data center infrastructure devices, and a first device data service component configured to service a request for a second portion of the device data, the second portion of the device data being different than the first portion of the device data. The system further includes a global server connected to each of the plurality of central servers through a network. The global server has an asynchronous event handling component configured to receive the first portion of the device data from the one or more central servers, a second device data service component configured to service a request for at least one of the first portion of the device data and the second portion of the device data, a data access component configured to maintain a database containing at least the first portion of the device data, and a data indexing component configured to generate and maintain an index of the first portion of the device data contained in the database. The index is configured to facilitate searching of the first portion of the device data.
"In another embodiment, the system may further include a global client connected to the global server. The global client may have a data requestor component configured to request at least one of the first portion of the device data and the second portion of the device data, and may further have a user interface configured to display at least one of the first portion of the device data and the second portion of the device data.
"In yet another embodiment, the global client may include a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the global client may include a data requestor component configured to request at least one of the first portion of the device data and the second portion of the device data, and may further be configured to display at least one of the first portion of the device data and the second portion of the device data.
"In another embodiment, the index may include a table of ordered records including at least one of the data, an occurrence frequency of the data, a database table name, and identification information for locating the data in the database.
"In another embodiment, the first portion of the device data may include a status of at least one of a data center server, a data center device, and a data center device group. The status may include at least one of sensor data, log data, and alarm data.
"According to another embodiment, a method of managing device data related to a data center infrastructure includes generating, by a first server, a first portion of the device data in response to a change in a status of at least one of a plurality of data center infrastructure devices, storing, by a second server, the first portion of the device data in a database, and generating an index, by the second server, of the first portion of the device data. The index is configured to facilitate searching of the first portion of the device data by the second server. The method further includes generating, by the first server, a second portion of the device data in response to a request for data that is not contained in the database. The second portion of the device data is different than the first portion of the device data and is generated in a lightweight format. The lightweight format is adapted for consumption by a thin client device. The method further includes displaying, in response to a user request, at least a portion of the first portion of the device data using a user interface that is provided to a client computer by the second server.
"In another embodiment, the method may further include searching, responsive to receiving a search request from a user, the first portion of the device data using the index to find data satisfying the search request.
"In yet another embodiment, the thin client device may include a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with at least one of the first server and the second server.
"In another embodiment, the method may further include automatically polling, by the second server, the first server to retrieve an update to the first portion of the device data.
"In another embodiment, the method may further include asynchronously transmitting to the second server, by the first server, an update to the first portion of the device data.
"In yet another embodiment, the method may further include generating a list of suggested search terms based on the first portion of the device data and on a user-supplied search query. The list of suggested search terms may include one or more terms derived from the first portion of the device data.
"In another embodiment, the user interface may be configured to display the list of suggested search terms to a user in response to receiving the user-supplied search query. The user interface may be further configured to enable the user to select one search term from the list of suggested search terms."
About Schneider Electric
Schneider Electric is the worldwide expert in energy administration and automation. With incomes of ~€25 billion in FY2016, our 144,000 representatives serve clients in more than 100 nations, Schneider Electric helping them to deal with their energy and process in ways that are protected, dependable, productive and practical. From the least difficult of changes to complex operational frameworks, Schneider Electric innovation, programming and administrations enhance the way our clients oversee and computerize their operations. Schneider Electric associated advancements reshape businesses, change urban communities and advance lives. At Schneider Electric, we call this Life Is On.
By a News Reporter-Staff News Editor at Computer Weekly News -- SCHNEIDER ELECTRIC IT CORPORATION (West Kingston, RI) has been issued patent number 9762578, according to news reporting originating out of Alexandria, Virginia, by VerticalNews editors.
The patent's inventors are Emerick, Gregory M. (O'Fallon, MO); Gifford, Paul J. (Somerset, MA).
This patent was filed by Schneider Electric on October 25, 2010 and was published online on September 12, 2017.
From the background information supplied by the inventors, news correspondents obtained the following quote: "The present invention relates generally to the field of secure network communications, and more particularly, to methods and systems for establishing secure authenticated bidirectional server communication using automated credential reservation.
"Data centers are widely used to house various types of electrical equipment, including computer systems and the physical infrastructure needed to support such systems, such as power supplies (e.g., uninterruptible power supplies and backup power supplies), environmental systems (e.g., air conditioning, fire suppression, etc.), physical data center security, and other monitoring devices. Companies that depend on the proper and efficient operation of their data centers use various tools to monitor and operate the physical infrastructure, including multiple monitoring systems that are coordinated to provide centralized collection and reporting of critical infrastructure events."
Supplementing the background information on this patent, VerticalNews reporters also obtained the inventors' summary information for this patent: "According to one embodiment, a method of authenticating communications includes acts of receiving, by a computer, a first set of credentials and verifying the first set of credentials by comparing the first set of credentials to a plurality of sets of credentials stored in a database. Subsequent to verifying the first set of credentials, the method further includes acts of deriving a second set of credentials, and transmitting notification of the second set of credentials to a remote computer.
"According to various embodiments, the act of verifying the first set of credentials may be performed by the remote computer. The first set of credentials may be created by a user of the computer. The first set of credentials may be created on the remote computer. The first set of credentials may include a username and password. At least one of the first set of credentials and the second set of credentials may be encrypted by the computer. The second set of credentials may be stored in a database accessible by the computer.
"In another embodiment, the method may further include an act of receiving, by the computer, contact information for the remote computer.
"In another embodiment, the method may further include an act of establishing, by the remote computer, secure communications with the computer using at least the second set of credentials.
"In yet another embodiment, the method may further comprise an act of automatically changing at least one of the first set of credentials and the second set of credentials using the at least one of the first set of credentials and the second set of credentials as a seed for calculating a new set of credentials to replace the at least one of the first set of credentials and the second set of credentials. The act of automatically changing may occur periodically. The act of automatically changing may occur in response to at least one of a user event, a system event, and a security event.
"According to another embodiment, a method of authenticating communications between a first computer and a second computer includes acts of receiving, from a user, a first set of credentials at the first computer; receiving, from the user, the first set of credentials at the second computer; calling, by the second computer, a first service operating on the first computer, the first service configured to provide verification of the first set of credentials to the second computer; responsive to receiving the verification of the first set of credentials from the second computer, deriving a second set of credentials by the second computer; and transmitting notification of the second set of credentials from the second computer to the first computer.
"In another embodiment, the method may further include an act of establishing, by the second computer, secure communications with the first computer using at least the second set of credentials.
"In another embodiment, the method may further include an act of establishing, by the first computer, secure communications with the second computer using at least the first set of credentials.
"In yet another embodiment, the method may further include an act of automatically changing at least one of the first set of credentials and the second set of credentials using the at least one of the first set of credentials and the second set of credentials as a seed for calculating a new set of credentials to replace the at least one of the first set of credentials and the second set of credentials. The act of automatically changing may occur periodically. The act of automatically changing may occur in response to at least one of a user event, a system event, and a security event.
"According to another embodiment, a data center infrastructure management system includes a network, a first server connected to the network, a plurality of data center infrastructure devices connected to the first server, the first server being configured to maintain device data related to management of the plurality of data center infrastructure devices, and a second server connected to the network and configured to verify a set of user-created credentials, to be supplied by the first server, by comparing the set of user-created credentials to a plurality of sets of user-created credentials stored in a database, the second server further configured to derive a set of server-created credentials based on the set of user-created credentials subsequent to verifying the set of user-created credentials, the second server further configured to notify the first server of the set of server-created credentials subsequent to deriving the set of server-created credentials. The first server uses the set of server-created credentials to establish secure communication with the second server for exchanging the device data with the second server.
"In another embodiment, the system may be configured to establish secure communication between the first server and a second server through the network using at least the set of used-created credentials and the set of server-created credentials.
"According to one embodiment, a data center infrastructure management system includes a plurality of central servers configured to maintain device data related to management of a plurality of data center infrastructure devices located within one or more data centers and a global server connected to the plurality of central servers through a first network. The global server is configured to receive at least a subset of the device data asynchronously from each of the plurality of central servers, and is further configured to store the at least the subset of the device data in a database, and is further configured to generate and maintain an index of the subset of the device data. The index is configured to facilitate searching of the subset of the device data in the database by the global server. The system further includes a global client connected to the global server through a second network, the global client having a user interface configured to request and receive from the global server at least one of a portion of the subset of the device data and a portion of the device data. The portion of the subset of the device data is to be located in the database using the index by the global server in response to the request, and the portion of the device data is to be received from the plurality of central servers in response to a request by the global client for data that is not in the database.
"In another embodiment, the global client may include a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the subset of the device data may includes data center asset inventory data.
"In yet another embodiment, the global server may be further configured to request the device data from the plurality of central servers in response to the request from the global client for the device data, wherein the device data is not stored in the database, and wherein the global server is further configured to provide the device data to the global client in a lightweight format subsequent to receiving the device data from the plurality of central servers. The lightweight format of the device data may be a format that is adapted for consumption by a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the global client may include a data requestor component configured to request at least one of the portion of the subset of the device data and the portion of the device data, and further configured to display the at least one of the portion of the subset of the device data and the portion of the device data.
"In another embodiment, the index may include a table of ordered records including at least one of the data, an occurrence frequency of the data, a database table name, and identification information for locating the data in the database.
"According to another embodiment, a Schneider Electric data center infrastructure management system includes a plurality of central servers configured to maintain device data related to management of a plurality of data center infrastructure devices located within one or more data centers. Each of the plurality of central servers has an asynchronous event component configured to automatically generate a first portion of the device data in response to a change in a status of at least one of the plurality of data center infrastructure devices, and a first device data service component configured to service a request for a second portion of the device data, the second portion of the device data being different than the first portion of the device data. The system further includes a global server connected to each of the plurality of central servers through a network. The global server has an asynchronous event handling component configured to receive the first portion of the device data from the one or more central servers, a second device data service component configured to service a request for at least one of the first portion of the device data and the second portion of the device data, a data access component configured to maintain a database containing at least the first portion of the device data, and a data indexing component configured to generate and maintain an index of the first portion of the device data contained in the database. The index is configured to facilitate searching of the first portion of the device data.
"In another embodiment, the system may further include a global client connected to the global server. The global client may have a data requestor component configured to request at least one of the first portion of the device data and the second portion of the device data, and may further have a user interface configured to display at least one of the first portion of the device data and the second portion of the device data.
"In yet another embodiment, the global client may include a thin client device that includes a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with the global server.
"In another embodiment, the global client may include a data requestor component configured to request at least one of the first portion of the device data and the second portion of the device data, and may further be configured to display at least one of the first portion of the device data and the second portion of the device data.
"In another embodiment, the index may include a table of ordered records including at least one of the data, an occurrence frequency of the data, a database table name, and identification information for locating the data in the database.
"In another embodiment, the first portion of the device data may include a status of at least one of a data center server, a data center device, and a data center device group. The status may include at least one of sensor data, log data, and alarm data.
"According to another embodiment, a method of managing device data related to a data center infrastructure includes generating, by a first server, a first portion of the device data in response to a change in a status of at least one of a plurality of data center infrastructure devices, storing, by a second server, the first portion of the device data in a database, and generating an index, by the second server, of the first portion of the device data. The index is configured to facilitate searching of the first portion of the device data by the second server. The method further includes generating, by the first server, a second portion of the device data in response to a request for data that is not contained in the database. The second portion of the device data is different than the first portion of the device data and is generated in a lightweight format. The lightweight format is adapted for consumption by a thin client device. The method further includes displaying, in response to a user request, at least a portion of the first portion of the device data using a user interface that is provided to a client computer by the second server.
"In another embodiment, the method may further include searching, responsive to receiving a search request from a user, the first portion of the device data using the index to find data satisfying the search request.
"In yet another embodiment, the thin client device may include a terminal having at least the components necessary for receiving input from a user, displaying output to the user, and communicating with at least one of the first server and the second server.
"In another embodiment, the method may further include automatically polling, by the second server, the first server to retrieve an update to the first portion of the device data.
"In another embodiment, the method may further include asynchronously transmitting to the second server, by the first server, an update to the first portion of the device data.
"In yet another embodiment, the method may further include generating a list of suggested search terms based on the first portion of the device data and on a user-supplied search query. The list of suggested search terms may include one or more terms derived from the first portion of the device data.
"In another embodiment, the user interface may be configured to display the list of suggested search terms to a user in response to receiving the user-supplied search query. The user interface may be further configured to enable the user to select one search term from the list of suggested search terms."
About Schneider Electric
Schneider Electric is the worldwide expert in energy administration and automation. With incomes of ~€25 billion in FY2016, our 144,000 representatives serve clients in more than 100 nations, Schneider Electric helping them to deal with their energy and process in ways that are protected, dependable, productive and practical. From the least difficult of changes to complex operational frameworks, Schneider Electric innovation, programming and administrations enhance the way our clients oversee and computerize their operations. Schneider Electric associated advancements reshape businesses, change urban communities and advance lives. At Schneider Electric, we call this Life Is On.