Patents by Inventor Shehzad T. Merchant
Shehzad T. Merchant has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 8707432Abstract: A wireless computer network includes components cooperating together to prevent access intrusions by detecting unauthorized devices connected to the network, disabling the network connections to the devices, and then physically locating the devices. The network can detect both unauthorized client stations and unauthorized edge devices such as wireless access points (APs). The network can detect intruders by monitoring information transferred over wireless channels, identifying protocol state machine violations, tracking roaming behavior of clients, and detecting network addresses being improperly used in multiple locations. Upon detecting an intruder, the network can automatically locate and shut off the physical/logical port to which the intruder is connected.Type: GrantFiled: December 20, 2007Date of Patent: April 22, 2014Assignee: Extreme Networks, Inc.Inventors: Manish M. Rathi, Vipin K. Jain, Shehzad T. Merchant, Victor C. Lin
-
Patent number: 7823199Abstract: A wireless computer network includes components cooperating together to prevent access intrusions by detecting unauthorized devices connected to the network, disabling the network connections to the devices, and then physically locating the devices. The network can detect both unauthorized client stations and unauthorized edge devices such as wireless access points (APs). The network can detect intruders by monitoring information transferred over wireless channels, identifying protocol state machine violations, tracking roaming behavior of clients, and detecting network addresses being improperly used in multiple locations. Upon detecting an intruder, the network can automatically locate and shut off the physical/logical port to which the intruder is connected.Type: GrantFiled: March 5, 2004Date of Patent: October 26, 2010Assignee: Extreme NetworksInventors: Manish M. Rathi, Vipin K. Jain, Shehzad T. Merchant, Victor C. Lin
-
Patent number: 7792058Abstract: A method and system for an aggregated virtual local area network (VLAN) architecture in which several VLANs in a network share the same default router address and subnet mask, but remain isolated from one another's network traffic. Instead of the traditional method of assigning one subnet to a VLAN, each VLAN is assigned only a portion of a subnet's IP address space, and is further grouped into a super-VLAN uniquely associated with that subnet. Intra-VLAN traffic is forwarded only to host IP addresses assigned to that same VLAN according to a VLAN identifier carried in the data packet. Inter-VLAN traffic is processed by a virtual router interface which routes the data packet by applying the routing configuration for the subnet uniquely associated with the super-VLAN, according to a super-VLAN identifier carried in the data packet.Type: GrantFiled: February 2, 2005Date of Patent: September 7, 2010Assignee: Extreme Networks, Inc.Inventors: Michael Yip, Shehzad T. Merchant, Kenneth T. Yin, Eric Knudstrup
-
Patent number: 7577996Abstract: Devices, systems and related methods are disclosed for improving operational security of a network and/or network devices, such as wireless access points (APs). In the disclosed systems, a network device is not fully operational until it is attached to a network and downloads sensitive information. The information is stored in the network device so that when the device is disconnected from the network, the sensitive information is erased from the device, making the device inoperative and removing sensitive information, such as passwords, network security keys, or the like. Disabling the network device in this manner not only prevents the theft of sensitive network access information, by also discourages theft of the device itself because it cannot be used on another network without the configuration information. In addition to downloading configuration information, the network device can also download an executable image that is likewise not permanently resident on the device.Type: GrantFiled: February 6, 2004Date of Patent: August 18, 2009Assignee: Extreme NetworksInventors: Shehzad T. Merchant, Derek H. Pitcher, Victor C. Lin, Manish M. Rathi, Jia-Ru Li, Matthew R. Peters, Balaji Srinivasan, Vipin K. Jain, Amit K. Maitra
-
Patent number: 7310664Abstract: A network switch having a unified, adaptive management paradigm for wireless network devices is disclosed. The switch includes configurable ports for connecting devices. A software application running on the switch allows a network administrator to selectively configure each port to support either a wired device or wireless device. Configuration information and software images that are needed for operation of the wireless device are associated with the port. When a wireless device is first plugged into the switch port, it downloads its configuration directly from the switch port. By storing the configuration information and images at the switch and automatically downloading them to the wireless devices, the task of configuring the devices is greatly simplified for the network administrator. This is particularly advantageous in heterogeneous network environments that support both wired and wireless devices, and where wireless device are readily moved to different ports.Type: GrantFiled: February 6, 2004Date of Patent: December 18, 2007Assignee: Extreme NetworksInventors: Shehzad T. Merchant, Manish M. Rathi, Victor C. Lin, Vipin K. Jain, Jia-Ru Li, Amit K. Maitra, Matthew R. Peters, Derek H. Pitcher, Balaji Srinivasan
-
Patent number: 7154861Abstract: A method and system is provided for a virtual local network to span multiple loop free network topology domains. According to one aspect of the invention, a network contains at least two loop free network topology domains and a virtual local area network spanning at least a portion of each of the two domains. According to one aspect of the invention, a network architecture comprises a plurality of nodes connected by paths, a first physical broadcast domain and a second physical broadcast domain each comprising a separate subset of the plurality of nodes, and a logical broadcast domain comprising a node from each subset.Type: GrantFiled: June 3, 2002Date of Patent: December 26, 2006Assignee: Extreme NetworksInventors: Shehzad T Merchant, Brian W Bailey
-
Patent number: 6914905Abstract: A method and system for an aggregated virtual local area network (VLAN) architecture in which several VLANs in a network share the same default router address and subnet mask, but remain isolated from one another's network traffic. Instead of the traditional method of assigning one subnet to a VLAN, each VLAN is assigned only a portion of a subnet's IP address space, and is further grouped into a super-VLAN uniquely associated with that subnet. Intra-VLAN traffic is forwarded only to host IP addresses assigned to that same VLAN according to a VLAN identifier carried in the data packet. Inter-VLAN traffic is processed by a virtual router interface which routes the data packet by applying the routing configuration for the subnet uniquely associated with the super-VLAN, according to a super-VLAN identifier carried in the data packet. The routing configuration used by the virtual router interface includes routing protocols, static routes, redundant router protocols and access-lists.Type: GrantFiled: June 16, 2000Date of Patent: July 5, 2005Assignee: Extreme Networks, Inc.Inventors: Michael Yip, Shehzad T. Merchant, Kenneth T. Yin
-
Patent number: 6859438Abstract: A flexible, policy-based, mechanism for managing, monitoring, and prioritizing traffic within a network and allocating bandwidth to achieve true quality of service (QoS) is provided. According to one aspect of the present invention, a method is provided for managing bandwidth allocation in a network that employs a non-deterministic access protocol, such as an Ethernet network. A packet forwarding device receives information indicative of a set of traffic groups, such as: a MAC address, or IEEE 802.1p priority indicator or 802.1Q frame tag, if the QoS policy is based upon individual station applications; or a physical port if the QoS policy is based purely upon topology. The packet forwarding device additionally receives bandwidth parameters corresponding to the traffic groups.Type: GrantFiled: December 5, 2003Date of Patent: February 22, 2005Assignee: Extreme Networks, Inc.Inventors: Stephen R. Haddock, Justin N. Chueh, Shehzad T. Merchant, Andrew H. Smith, Michael Yip
-
Publication number: 20040081093Abstract: A flexible, policy-based, mechanism for managing, monitoring, and prioritizing traffic within a network and allocating bandwidth to achieve true quality of service (QoS) is provided. According to one aspect of the present invention, a method is provided for managing bandwidth allocation in a network that employs a non-deterministic access protocol, such as an Ethernet network. A packet forwarding device receives information indicative of a set of traffic groups, such as: a MAC address, or IEEE 802.1p priority indicator or 802.1Q frame tag, if the QoS policy is based upon individual station applications; or a physical port if the QoS policy is based purely upon topology. The packet forwarding device additionally receives bandwidth parameters corresponding to the traffic groups.Type: ApplicationFiled: December 5, 2003Publication date: April 29, 2004Inventors: Stephen R. Haddock, Justin N. Chueh, Shehzad T. Merchant, Andrew H. Smith, Michael Yip
-
Patent number: 6678248Abstract: A flexible, policy-based, mechanism for managing, monitoring, and prioritizing traffic within a network and allocating bandwidth to achieve true quality of service (QoS) is provided. According to one aspect of the present invention, a method is provided for managing bandwidth allocation in a network that employs a non-deterministic access protocol, such as an Ethernet network. A packet forwarding device receives information indicative of a set of traffic groups, such as: a MAC address, or IEEE 802.1p priority indicator or 802.1Q frame tag, if the QoS policy is based upon individual station applications; or a physical port if the QoS policy is based purely upon topology. The packet forwarding device additionally receives bandwidth parameters corresponding to the traffic groups.Type: GrantFiled: June 20, 2000Date of Patent: January 13, 2004Assignee: Extreme NetworksInventors: Stephen R. Haddock, Justin N. Chueh, Shehzad T. Merchant, Andrew H. Smith, Michael Yip
-
Patent number: 6104700Abstract: A flexible, policy-based, mechanism for managing, monitoring, and prioritizing traffic within a network and allocating bandwidth to achieve true quality of service (QoS) is provided. According to one aspect of the present invention, a method is provided for managing bandwidth allocation in a network that employs a non-deterministic access protocol, such as an Ethernet network. A packet forwarding device receives information indicative of a set of traffic groups, such as: a MAC address, or IEEE 802.1p priority indicator or 802.1Q frame tag, if the QoS policy is based upon individual station applications; or a physical port if the QoS policy is based purely upon topology. The packet forwarding device additionally receives bandwidth parameters corresponding to the traffic groups.Type: GrantFiled: February 3, 1998Date of Patent: August 15, 2000Assignee: Extreme NetworksInventors: Stephen R. Haddock, Justin N. Chueh, Shehzad T. Merchant, Andrew H. Smith, Michael Yip