Patents by Inventor Roy M. Brooks

Roy M. Brooks has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9509720
    Abstract: Techniques are presented herein for attesting the trustworthiness of devices in a secure network during run-time operation. A security management device is configured to perform network trust attestation operations in order to generate an access control policy that defines access rights for a device in a network. The access control policy is assured by creating a hash value for the access control policy and then signing the hash value to generate a signed hash value. The signed hash value is integrated with the access control policy, and the access control policy is sent with the signed hash value to the operator device for verification.
    Type: Grant
    Filed: June 12, 2014
    Date of Patent: November 29, 2016
    Assignee: Cisco Technology, Inc.
    Inventors: Chris A. Shenefiel, Rafael Mantilla Montalvo, Roy M. Brooks
  • Publication number: 20150365436
    Abstract: Techniques are presented herein for attesting the trustworthiness of devices in a secure network during run-time operation. A security management device is configured to perform network trust attestation operations in order to generate an access control policy that defines access rights for a device in a network. The access control policy is assured by creating a hash value for the access control policy and then signing the hash value to generate a signed hash value. The signed hash value is integrated with the access control policy, and the access control policy is sent with the signed hash value to the operator device for verification.
    Type: Application
    Filed: June 12, 2014
    Publication date: December 17, 2015
    Inventors: Chris A. Shenefiel, Rafael Mantilla Montalvo, Roy M. Brooks
  • Patent number: 8737406
    Abstract: An improved technique for distributing routing information that allows routes to be prioritized such that information associated with higher priority routes is sent in update messages ahead of information associated with lower priority routes, thereby enabling the higher priority routes to converge faster than the lower priority routes. In the preferred embodiment of the invention a route policy map that associates routes with priorities is defined. The policy map is then applied to the routes to prioritize the routes. Update messages are then generated using the priority information and the route information contained in the update messages is organized such that route information associated with higher priority routes is placed ahead of route information associated with lower priority routes.
    Type: Grant
    Filed: August 1, 2002
    Date of Patent: May 27, 2014
    Assignee: Cisco Technology, Inc.
    Inventors: John E. Cavanaugh, Roy M. Brooks, Matthew H. Birkner
  • Patent number: 7936668
    Abstract: A given router in the core of a label-switching network identifies a group of routers to receive common label binding information for later routing packets along respective paths through the label-switching network. One way to identify which of multiple routers to include as a member of the group to receive the same label information is to analyze egress policies associated with downstream routers in the label-switching network. Based on this analysis, the given router identifies group members as routers having a substantially same egress policy as each other. The given router then allocates memory resources to store a common set of label information to be distributed to each member in the group of routers having the same egress policy. After populating the memory resources with label information, the given router distributes a common set of label information to each router in the group of routers.
    Type: Grant
    Filed: May 26, 2005
    Date of Patent: May 3, 2011
    Assignee: Cisco Technology, Inc.
    Inventors: James N. Guichard, Matthew H. Birkner, Robert H. Thomas, Roy M. Brooks
  • Patent number: 7409712
    Abstract: Conventional methods of addressing a Distributed Denial of Service attack include taking the target node offline, and routing all traffic to an alternate countermeasure, or “sinkhole” router, therefore requiring substantial lag time to reconfigure the target router into the network. In a network, a system operator monitors a network for undesirable message traffic. Upon a notification of such undesirable message traffic, traffic is rerouted to a filter complex to separate undesirable traffic. The filter complex establishes an alternate route using a second communications protocol, and uses the alternate route to redirect the desirable message traffic to the target node. The use of the second protocol avoids conflict between the redirected desirable traffic and the original, or first, protocol which now performs the reroute.
    Type: Grant
    Filed: July 16, 2003
    Date of Patent: August 5, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: Roy M. Brooks, John E. Cavanaugh, Paul M. Quinn