Patents by Inventor Chien-Cheng Wang

Chien-Cheng Wang has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8261350
    Abstract: A system for preventing successful denial of service attacks comprises a first communication device, a second communication device, and a network. The first and second communication devices establish a communication session via the network. Based on various information, such as a pre-shared secret, one of the communication devices determines a network access filter value and compares this value to at least one data frame in order to authenticate such data frame without committing significant computing resource and any memory space. By updating the network access filter over time, an unauthorized user who discovers the outdated network access filter values is prevented from successfully launching a denial of service attack.
    Type: Grant
    Filed: January 5, 2011
    Date of Patent: September 4, 2012
    Assignee: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang, Chun-Ching Huang
  • Publication number: 20120124383
    Abstract: The present disclosure generally pertains to systems and methods for protecting network resources from denial of service attacks. In one exemplary embodiment, a responder stores an access filter value used to determine whether an incoming message frame has been transmitted from an authorized user. In this regard, a user communication device includes logic for determining the access filter value stored at the responder and, includes the access filter value in a message frame transmitted from the computer to the responder. The responder compares the received access filter value to the stored access filter value. If such values match or otherwise correspond, the responder authenticates the message frame. However, if such values do not match or otherwise correspond, the responder discards the message frame. Thus, the responder processes authenticated message frames and discards unauthenticated message frames thereby preventing denial of service attacks from malicious users.
    Type: Application
    Filed: January 19, 2012
    Publication date: May 17, 2012
    Applicant: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang
  • Patent number: 8127355
    Abstract: The present disclosure generally pertains to systems and methods for protecting network resources from denial of service attacks. In one exemplary embodiment, a responder stores an access filter value used to determine whether an incoming message frame has been transmitted from an authorized user. In this regard, a user communication device includes logic for determining the access filter value stored at the responder and includes the access filter value in a message frame transmitted from the computer to the responder. The responder compares the received access filter value to the stored access filter value. If such values match or otherwise correspond, the responder authenticates the message frame. However, if such values do not match or otherwise correspond, the responder discards the message frame. Thus, the responder processes authenticated message frames and discards unauthenticated message frames thereby preventing denial of service attacks from malicious users.
    Type: Grant
    Filed: June 1, 2010
    Date of Patent: February 28, 2012
    Assignee: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang
  • Patent number: 7937759
    Abstract: A system for preventing successful denial of service attacks comprises a first communication device, a second communication device, and a network. The first and second communication devices establish a communication session via the network. Based on various information, such as a pre-shared secret, one of the communication devices determines a network access filter value and compares this value to at least one data frame in order to authenticate such data frame without committing significant computing resource and any memory space. By updating the network access filter over time, an unauthorized user who discovers the outdated network access filter values is prevented from successfully launching a denial of service attack.
    Type: Grant
    Filed: March 30, 2007
    Date of Patent: May 3, 2011
    Assignee: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang, Chun-Ching Huang
  • Publication number: 20110099630
    Abstract: A system for preventing successful denial of service attacks comprises a first communication device, a second communication device, and a network. The first and second communication devices establish a communication session via the network. Based on various information, such as a pre-shared secret, one of the communication devices determines a network access filter value and compares this value to at least one data frame in order to authenticate such data frame without committing significant computing resource and any memory space. By updating the network access filter over time, an unauthorized user who discovers the outdated network access filter values is prevented from successfully launching a denial of service attack.
    Type: Application
    Filed: January 5, 2011
    Publication date: April 28, 2011
    Applicant: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang, Chun-Ching Huang
  • Publication number: 20100242112
    Abstract: The present disclosure generally pertains to systems and methods for protecting network resources from denial of service attacks. In one exemplary embodiment, a responder stores an access filter value used to determine whether an incoming message frame has been transmitted from an authorized user. In this regard, a user communication device includes logic for determining the access filter value stored at the responder and includes the access filter value in a message frame transmitted from the computer to the responder. The responder compares the received access filter value to the stored access filter value. If such values match or otherwise correspond, the responder authenticates the message frame. However, if such values do not match or otherwise correspond, the responder discards the message frame. Thus, the responder processes authenticated message frames and discards unauthenticated message frames thereby preventing denial of service attacks from malicious users.
    Type: Application
    Filed: June 1, 2010
    Publication date: September 23, 2010
    Applicant: Auburn University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang
  • Patent number: 7774841
    Abstract: The present disclosure generally pertains to systems and methods for protecting network resources from denial of service attacks. In one exemplary embodiment, a responder stores an access filter value used to determine whether an incoming message frame has been transmitted from an authorized user. In this regard, a user communication device includes logic for determining the access filter value stored at the responder and includes the access filter value in a message frame transmitted from the computer to the responder. The responder compares the received access filter value to the stored access filter value. If such values match or otherwise correspond, the responder authenticates the message frame. However, if such values do not match or otherwise correspond, the responder discards the message frame. Thus, the responder processes authenticated message frames and discards unauthenticated message frames thereby preventing denial of service attacks from malicious users.
    Type: Grant
    Filed: October 1, 2004
    Date of Patent: August 10, 2010
    Assignee: Aubum University
    Inventors: Chwan-Hwa Wu, J. David Irwin, Chien-Cheng Wang
  • Publication number: 20070266241
    Abstract: A system for preventing successful denial of service attacks comprises a first communication device, a second communication device, and a network. The first and second communication devices establish a communication session via the network. Based on various information, such as a pre-shared secret, one of the communication devices determines a network access filter value and compares this value to at least one data frame in order to authenticate such data frame without committing significant computing resource and any memory space. By updating the network access filter over time, an unauthorized user who discovers the outdated network access filter values is prevented from successfully launching a denial of service attack.
    Type: Application
    Filed: March 30, 2007
    Publication date: November 15, 2007
    Inventors: Chwan-Hwa Wu, J. Irwin, Chien-Cheng Wang, Chun-Ching Huang
  • Publication number: 20050144352
    Abstract: A system for buffering data received from a network comprises a network socket, a plurality of buffers, a buffer pointer pool, receive logic, and packet delivery logic. The buffer pointer pool has a plurality of entries respectively pointing to the buffers. The receive logic is configured to pull an entry from the pool and to perform a bulk read of the network socket. The entry points to one of the buffers, and the receive logic is further configured to store data from the bulk read to the one buffer based on the entry. The packet delivery logic is configured to read, based on the entry, the one buffer and to locate a missing packet sequence in response to a determination, by the packet delivery logic, that the one buffer is storing an incomplete packet sequence. The packet delivery logic is further configured to form a complete packet sequence based on the incomplete packet sequence and the missing packet sequence.
    Type: Application
    Filed: October 1, 2004
    Publication date: June 30, 2005
    Inventors: Chwan-Hwa Wu, J. Irwin, Chien-Cheng Wang