Patents by Inventor Avinash Shah

Avinash Shah has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12688313
    Abstract: Disclosed are methods, controllers, and computer-readable media that explicitly label data packets and interfaces as trusted or untrusted. The data packet labeling can occur at a centralized security hub or at the enforcement site itself, i.e., at the interface to the trusted or untrusted region. The packet can be labeled with metadata associated with the packet, and that label can be carried through the transport of the packet to avoid overbroad or unnecessary security procedures. Further, a network administrator can designate certain links as trusted or untrusted so that packets designated as trusted can be sent down trusted links, and untrusted traffic can be sent down untrusted links. Network resources are saved while traffic is better separated and allocated down links with trustworthiness that is congruent with that of the packet.
    Type: Grant
    Filed: June 25, 2024
    Date of Patent: July 21, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Pritam Baruah, Amjad Inamdar, Avinash Shah, Sagar Soni, Hari Krishna Donti
  • Patent number: 12671414
    Abstract: A circuit incudes: a first transistor; a capacitor; a second transistor; and a second resistor. The first transistor has a current terminal and a first control terminal. The capacitor has a capacitor terminal coupled to the current terminal of the first transistor. The second transistor has a first current terminal, a second current terminal, and a second control terminal. The first current terminal of the second transistor is coupled to the capacitor terminal. The second current terminal of the second transistor is coupled to the first control terminal. The resistor has a resistor terminal coupled to the second control terminal.
    Type: Grant
    Filed: March 31, 2023
    Date of Patent: June 30, 2026
    Assignee: TEXAS INSTRUMENTS INCORPORATED
    Inventors: Avinash Shah, Kashyap Barot, Sreeram Nasum S
  • Publication number: 20260181685
    Abstract: In one embodiment, a method for SD-WAN tunnel resiliency in high scale networks includes maintaining a plurality of pools of resources reserved for network tunnels where the plurality of pools having a primary pool, a first backup pool for network tunnels assigned a first priority, and a second backup pool for network tunnels assigned a second priority and determining, by the process, that the primary pool contains insufficient resources to form a new network tunnel. The method further includes determining, in response to the primary pool containing insufficient resources, a priority assigned to the new network tunnel and forming, when the priority assigned to the new network tunnel meets a particular criterion, the new network tunnel by using resources from either the first backup pool or the second backup pool based on the priority assigned to the new network tunnel and whether the first backup pool or the second backup pool contain sufficient resources to form the new network tunnel.
    Type: Application
    Filed: December 24, 2024
    Publication date: June 25, 2026
    Inventors: Ganesh DEVENDRACHAR, Avinash SHAH, Arul Murugan MANICKAM, Satyajit DAS, Murthy Nagaraja RAGHAVENDRA, Balaji SUNDARARAJAN
  • Publication number: 20260172346
    Abstract: Techniques are described herein for optimizing routing of network traffic to a DIA connection. In embodiments, the techniques may be performed by an edge device operating on a LAN and may comprise receiving an advertisement message from a second device, the advertisement message including an indication of at least one second Direct Internet Access (DIA) connection accessible from the second device and updating a local routing table to include the indication of the at least one second DIA connection. The techniques may then comprise receiving network traffic to be routed over an external network, upon determining that the first DIA connection is unavailable, selecting the at least one second DIA connection based on the information in the local routing table, and forwarding the network traffic to the second device.
    Type: Application
    Filed: March 7, 2025
    Publication date: June 18, 2026
    Inventors: Pritam Baruah, Sampath Kumar Sthothra Bhasham, Avinash Shah, Arul Murugan Manickam
  • Patent number: 12647343
    Abstract: The present disclosure includes systems and methods for symmetric routing and split-brain handling in high-availability (HA) networks using route priority and route affinity inversion. In one aspect, the method includes receiving, at a controller associated with a communication network, first status information associated with at least one of a first node or a second node. The first node and the second node are used in service of a first VPN. The controller determines, from the first status information, a preference associated with the first node over the second node for servicing traffic of the first VPN, and generates routing information for a third node of the communication network. The routing information specifies that the first node is preferred for serving traffic of the first VPN, and that the second node is available, but less preferred for servicing traffic of the first VPN.
    Type: Grant
    Filed: January 30, 2024
    Date of Patent: June 2, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Arul Murugan Manickam, Satyajit Das, Avinash Shah, Pritam Baruah, Michael Tracy, Satish Kumar Mahadevan
  • Patent number: 12647350
    Abstract: Techniques are described herein for providing bi-directional path selection based on indicated path preferences in policy data. Such techniques may be performed by a network node and may comprise generating a set of paths to a destination, a first path of the set of paths being labeled as a direct path and a second path of the set of paths being labeled as an indirect path. Such techniques may subsequently comprise receiving a communication from a source and directed to the destination, determining, based on a first indicated path preference for the destination and a second indicated path preference for the source, a path category, selecting a forwarding path as one of the first path or the second path based on the determined path category, and routing the communication to a next hop in the selected forwarding path.
    Type: Grant
    Filed: March 18, 2024
    Date of Patent: June 2, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Pritam Baruah, Satish Mahadevan, Avinash Shah, Sanjay Sreenath
  • Publication number: 20260142917
    Abstract: A system facilitates communication between branches of an SD-WAN and a service chain element. A hub node receives a data packet of a flow from a source branch over a VPN segment to be transmitted to a destination branch, extracts flow information from the data packet including VPN segment information to be stored in a flow table before transmitting the data packet to the service chain element over a service chain VPN. Upon return of the data packet from the service chain element, the hub node uses packet tuple information to retrieve the flow information with VPN segment information from the flow table. The hub node can then forward the data packet to the destination branch over the VPN segment. The hub node can generate and store an Auto Service Chaining Key that connects bidirectional flows so that the hub node can apply service-chaining to bidirectional traffic.
    Type: Application
    Filed: January 12, 2026
    Publication date: May 21, 2026
    Inventors: Avinash Shah, Pritam Baruah, Amjad Inamdar, Laxmikantha Reddy Ponnuru, Latika Ahuja, Jai Prakash Agrawal
  • Publication number: 20260135802
    Abstract: One or more aspects of the present disclosure are directed to providing a single hierarchical construct for defining requirements (connectivity parameters) of a service in a service chain. In one aspect, a single construct for identifying a service in a service chain includes a first object identifying at least one path for accessing an instance of the service within a communication network, a second object identifying a respective communication protocol for the at least one path; and a third object identifying at least a transmission specification for the respective communication protocol in the second object, wherein the second object and the third object are embedded within the first object.
    Type: Application
    Filed: January 8, 2026
    Publication date: May 14, 2026
    Inventors: Pritam Baruah, Amjad Inamdar, Laxmikantha Reddy Ponnuru, Avinash Shah, Jai Prakash Agrawal
  • Publication number: 20260067213
    Abstract: A system and method are provided for securely routing data through a series of overlay networks without decrypting and encrypting at boundaries between the overlay networks. The packet is routed through first and second overlay networks, and a second overlay network using a header in which the destination-address field encodes both a nexthop destination address and one or more lookup indices that uniquely that are used to look up subsequent nexthop destination addresses. Using a current destination address in the header, the packet is forwarded through the first overlay network to a first router between the overlay networks. A lookup index in the header is used to look up the next destination address (i.e., a transport address across the second overlay network to a second router), which overwrites the current destination address, so that the modified header can be used to forward the packet to the second router.
    Type: Application
    Filed: August 29, 2024
    Publication date: March 5, 2026
    Inventors: Lianxiang Wang, Bin Shi, Avinash Shah, Alan Xiao-rong Wang, Yunpeng Zhang, Pan Wu
  • Publication number: 20260067214
    Abstract: In one aspect, a method includes receiving, at a first router, a data packet from a network device via a communication channel, executing, by the first router, a policy lookup for the data packet to determine a policy action for handling the data packet, including, by the first router, the policy action in a header of the data packet, and transmitting, by the first router, the data packet to a second router where the second router processes the data packet based on the policy action included in the header of the data packet.
    Type: Application
    Filed: January 23, 2025
    Publication date: March 5, 2026
    Inventors: Arul Murugan Manickam, Pritam Baruah, Avinash Shah, Sampath Sthothra Bhasham
  • Patent number: 12562993
    Abstract: Techniques are described for detecting a change in Path Maximum Transfer Unit (PMTU) in a network and initiating a PMTU discovery process. A Bidirectional Forwarding Detection (BFD) data packet is generated having enhanced headers configured to record a largest packet sent value and a largest packet received value. The BFD data packet is sent from a first network device (such as a first router) to a second network device (such as a second router). A largest packet sent value and a largest packet received value are each recorded in the BFD data packet. If the largest data packet sent value is larger than the largest data packet received value, then a determination can be made that a path change has resulted in a reduction in PMTU which has resulted in either a data packet being fragmented, a data packet being dropped or both. A PMTU discovery can then be performed.
    Type: Grant
    Filed: June 9, 2023
    Date of Patent: February 24, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Avinash Shah, Ganesh Devendrachar, Arul Murugan Manickam, Laxmikantha Reddy Ponnuru, Satyajit Das, Pritam Baruah
  • Patent number: 12556476
    Abstract: A system facilitates communication between branches of an SD-WAN and a service chain element. A hub node receives a data packet of a flow from a source branch over a VPN segment to be transmitted to a destination branch, extracts flow information from the data packet including VPN segment information to be stored in a flow table before transmitting the data packet to the service chain element over a service chain VPN. Upon return of the data packet from the service chain element, the hub node uses packet tuple information to retrieve the flow information with VPN segment information from the flow table. The hub node can then forward the data packet to the destination branch over the VPN segment. The hub node can generate and store an Auto Service Chaining Key that connects bidirectional flows so that the hub node can apply service-chaining to bidirectional traffic.
    Type: Grant
    Filed: September 21, 2023
    Date of Patent: February 17, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Avinash Shah, Pritam Baruah, Amjad Inamdar, Laxmikantha Reddy Ponnuru, Latika Ahuja, Jai Prakash Agrawal
  • Patent number: 12549481
    Abstract: The present technology carries a calculated hash value from a standby node to an active node in an HA cluster when the packet is redirected to the active node. The hash value calculated at the standby node can be placed in the peer divert header during inner Layer 3 processing and carried to the active node in a local data bus or data line. The active node can then decode the hash value received from the standby node using the divert header. In doing so, security is preserved for the transmitted packet, but the active node can also load balance the packet based on the hash value calculated by the standby node.
    Type: Grant
    Filed: July 15, 2024
    Date of Patent: February 10, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Arul Murugan Manickam, Pritam Baruah, Avinash Shah, Amulya Kundur
  • Patent number: 12549472
    Abstract: One or more aspects of the present disclosure are directed to providing a single hierarchical construct for defining requirements (connectivity parameters) of a service in a service chain. In one aspect, a single construct for identifying a service in a service chain includes a first object identifying at least one path for accessing an instance of the service within a communication network, a second object identifying a respective communication protocol for the at least one path; and a third object identifying at least a transmission specification for the respective communication protocol in the second object, wherein the second object and the third object are embedded within the first object.
    Type: Grant
    Filed: July 6, 2023
    Date of Patent: February 10, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Pritam Baruah, Amjad Inamdar, Laxmikantha Reddy Ponnuru, Avinash Shah, Jai Prakash Agrawal
  • Patent number: 12537770
    Abstract: In one embodiment, a method includes receiving traffic and identifying one or more attributes associated with the traffic. The method also includes dynamically selecting a load balancing algorithm based on the one or more attributes in accordance with a load balancing scheme. The method further includes performing load balancing on the traffic in accordance with the load balancing algorithm and communicating the traffic from a first network element to a second network element in accordance with the load balancing.
    Type: Grant
    Filed: August 2, 2022
    Date of Patent: January 27, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Arul Murugan Manickam, Avinash Shah, Laxmikantha Reddy Ponnuru, Satyajit Das, Deepa Rajendra Sangolli, Govindakrishnan Kannan, Pritam Baruah
  • Patent number: 12519721
    Abstract: A system facilitates communication between branches of an SD-WAN and a service chain element. A hub node receives a data packet of a flow from a source branch over a VPN segment to be transmitted to a destination branch, extracts flow information from the data packet including VPN segment information to be stored in a flow table before transmitting the data packet to the service chain element over a service chain VPN. Upon return of the data packet from the service chain element, the hub node uses packet tuple information to retrieve the flow information with VPN segment information from the flow table. The hub node can then forward the data packet to the destination branch over the VPN segment. The hub node can generate and store an Auto Service Chaining Key that connects bidirectional flows so that the hub node can apply service-chaining to bidirectional traffic.
    Type: Grant
    Filed: September 21, 2023
    Date of Patent: January 6, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Avinash Shah, Pritam Baruah, Amjad Inamdar, Laxmikantha Reddy Ponnuru, Latika Ahuja, Jai Prakash Agrawal
  • Publication number: 20260005976
    Abstract: Techniques are described for avoiding data packet fragmentation in a routing device such as a router or network switch. Path Maximum Transport Unit (PMTU) values are monitored for a plurality of egress links of a networking device. A statistical analysis of fragmentation rates is performed. The statistical analysis can be performed on a per-link basis, per-flow basis or both per-link and per-flow basis. If the packet fragmentation rate of data flows through a particular egress link exceeds a determined threshold value, one or more data flows can be re-routed to a different egress link having a higher PMTU, thereby preventing data packet fragmentation.
    Type: Application
    Filed: September 8, 2025
    Publication date: January 1, 2026
    Inventors: Balaji Sundararajan, Ganesh Devendrachar, Avinash Shah, Preety Mordani, Satyajit Das, Michael John Moskal
  • Publication number: 20250392546
    Abstract: Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
    Type: Application
    Filed: August 20, 2025
    Publication date: December 25, 2025
    Inventors: Steven Wood, Balaji Sundararajan, Laxmikantha Reddy Ponnuru, Avinash Shah, Pritam Baruah, Venkatesh Nataraj, Ganesh Devendrachar
  • Publication number: 20250322084
    Abstract: Disclosed are methods, controllers, and computer-readable media that explicitly label data packets and interfaces as trusted or untrusted. The data packet labeling can occur at a centralized security hub or at the enforcement site itself, i.e., at the interface to the trusted or untrusted region. The packet can be labeled with metadata associated with the packet, and that label can be carried through the transport of the packet to avoid overbroad or unnecessary security procedures. Further, a network administrator can designate certain links as trusted or untrusted so that packets designated as trusted can be sent down trusted links, and untrusted traffic can be sent down untrusted links. Network resources are saved while traffic is better separated and allocated down links with trustworthiness that is congruent with that of the packet.
    Type: Application
    Filed: June 25, 2024
    Publication date: October 16, 2025
    Inventors: Pritam Baruah, Amjad Inamdar, Avinash Shah, Sagar Soni, Hari Krishna Donti
  • Publication number: 20250317391
    Abstract: The present technology carries a calculated hash value from a standby node to an active node in an HA cluster when the packet is redirected to the active node. The hash value calculated at the standby node can be placed in the peer divert header during inner Layer 3 processing and carried to the active node in a local data bus or data line. The active node can then decode the hash value received from the standby node using the divert header. In doing so, security is preserved for the transmitted packet, but the active node can also load balance the packet based on the hash value calculated by the standby node.
    Type: Application
    Filed: July 15, 2024
    Publication date: October 9, 2025
    Inventors: Arul Murugan Manickam, Pritam Baruah, Avinash Shah, Amulya Kundur