Patents by Inventor Edward C. Kersey
Edward C. Kersey has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 9350715Abstract: A data security device for providing a network transport connection via a transparent network proxy that employs different encryption security mediums along a communications session between two endpoints by emulating one of the endpoints at an intermediate node such that the communication session appears as an atomic, secure connection to the endpoints yet provides appropriate security over the end-to-end connection. A sender node sends a connection request to establish a secure communication session with an intended receiver node. A transparent proxy on an intermediate node receives the request and establishes the link employing an encryption mechanism. The transparent proxy establishes a second link with the intended receiver, and applies a second, less expensive encryption mechanism. The transparent proxy combines the two links to form the trusted, secure connection but incurring only the mitigated expense over the second link.Type: GrantFiled: March 15, 2013Date of Patent: May 24, 2016Assignee: CISCO TECHNOLOGY, INC.Inventors: Edward C. Kersey, James W. O'Toole, Jr., Bradley Dale Dike, Patrick Darrell Tate, Eric A. Fritzges, Andre Justin Pecqueur, Bruce F. Wong, Hema M. Prasad, Shaheed Bacchus, Larry David Bisel
-
Patent number: 8452956Abstract: A data security device for providing a network transport connection via a transparent network proxy that employs different encryption security mediums along a communications session between two endpoints by emulating one of the endpoints at an intermediate node such that the communication session appears as an atomic, secure connection to the endpoints yet provides appropriate security over the end-to-end connection. A sender node sends a connection request to establish a secure communication session with an intended receiver node. A transparent proxy on an intermediate node receives the request and establishes the link employing an encryption mechanism. The transparent proxy establishes a second link with the intended receiver, and applies a second, less expensive encryption mechanism. The transparent proxy combines the two links to form the trusted, secure connection but incurring only the mitigated expense over the second link.Type: GrantFiled: February 20, 2009Date of Patent: May 28, 2013Assignee: Cisco Technology, Inc.Inventors: Edward C. Kersey, James W. O'Toole, Jr., Bradley Dale Dike, Patrick Darrell Tate, Eric A. Fritzges, Andre Justin Pecqueur, Bruce F. Wong, Hema M. Prasad, Shaheed Bacchus, Larry David Bisel
-
Patent number: 8332625Abstract: A method, apparatus and computer program product for providing failover capability of cached secure sessions is presented. A cached secure session involving a first device and a second device is identified. The cached secure session is encrypted and replicated to a failover device. The encrypted session is then decrypted on the failover to device. An occurrence of a hot failover involving the second device is detected, and processing resumes between the first device and the failover device.Type: GrantFiled: August 22, 2011Date of Patent: December 11, 2012Assignee: Cisco Technology, Inc.Inventors: Eric A. Fritzges, Larry D. Bisel, Edward C. Kersey, Patrick D. Tate, Bruce F. Wong, Bradley D. Dike, Andre Justin Pecqueur, Shaheed Bacchus
-
Publication number: 20110307692Abstract: A method, apparatus and computer program product for providing failover capability of cached secure sessions is presented. A cached secure session involving a first device and a second device is identified. The cached secure session is encrypted and replicated to a failover device. The encrypted session is then decrypted on the failover to device.Type: ApplicationFiled: August 22, 2011Publication date: December 15, 2011Inventors: Eric A. Fritzges, Larry D. Bisel, Edward C. Kersey, Patrick D. Tate, Bruce F. Wong, Bradley D. Dike, Andre Justin Pecqueur, Shaheed Bacchus
-
Patent number: 8006091Abstract: A method, apparatus and computer program product for providing failover capability of cached secure sessions is presented. A cached secure session involving a first device and a second device is identified. The cached secure session is encrypted and replicated to a failover device. The encrypted session is then decrypted on the failover device. An occurrence of a hot failover involving the second device is detected, and processing resumes between the first device and the failover device.Type: GrantFiled: January 10, 2005Date of Patent: August 23, 2011Assignee: Cisco Technology, Inc.Inventors: Eric A. Fritzges, Larry D. Bisel, Edward C. Kersey, Patrick D. Tate, Bruce F. Wong, Bradley D. Dike, Andre Justin Pecqueur, Shaheed Bacchus
-
Patent number: 7730190Abstract: Disclosed is a system and method for distributing connections among a plurality of servers at an Internet site. All connections are made to a single IP address and a local director selects the server from among the plurality of servers which is to receive the connection. Thus, the DNS server is not relied upon to distribute connections, and the connection distribution scheme is not avoided when DNS is bypassed. In one embodiment, a session distribution scheme is implemented such that connections are distributed to the server in the group of servers which has the fewest connections of the group. In other embodiments, other session distribution schemes which route connections based on the predicted response times of the servers or according to a round robin scheme are used.Type: GrantFiled: December 4, 2006Date of Patent: June 1, 2010Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey, Peter A. Tenereillo
-
Patent number: 7506368Abstract: A data security device for providing a network transport connection via a transparent network proxy that employs different encryption security mediums along a communications session between two endpoints by emulating one of the endpoints at an intermediate node such that the communication session appears as an atomic, secure connection to the endpoints yet provides appropriate security over the end-to-end connection. A sender node sends a connection request to establish a secure communication session with an intended receiver node. A transparent proxy on an intermediate node receives the request and establishes the link employing an encryption mechanism. The transparent proxy establishes a second link with the intended receiver, and applies a second, less expensive encryption mechanism. The transparent proxy combines the two links to form the trusted, secure connection but incurring only the mitigated expense over the second link.Type: GrantFiled: February 13, 2003Date of Patent: March 17, 2009Assignee: Cisco Technology, Inc.Inventors: Edward C. Kersey, James W. O'Toole, Jr., Bradley Dale Dike, Patrick Darrell Tate, Eric A. Fritzges, Andre Justin Pecqueur, Bruce F. Wong, Hema M. Prasad, Shaheed Bacchus, Larry David Bisel
-
Patent number: 7480794Abstract: Conventional SSL termination devices support secure connections only to a predetermined destination address. An SSL termination device accepts a plaintext connection and associate it to a secure connection to an arbitrary destination endpoint by intercepting a connection request from the local subnetwork, identifying the intended destination of the connection, and establishing a secure connection to the destination, bridges the local connection and the secure connection to provide a connection through the gateway device. The SSL termination device identifies an outgoing secure connection request from a client, and intercepts the connection request to identify the recipient destination. The SSL termination device establishes a secure connection using the identified destination, and associates the connections by mapping the intercepted connection to the recipient.Type: GrantFiled: September 22, 2004Date of Patent: January 20, 2009Assignee: Cisco Technology, Inc.Inventors: Edward C. Kersey, Derek L. Huckaby
-
Patent number: 7146417Abstract: Disclosed is a system and method for distributing connections among a plurality of servers at an Internet site. All connections are made to a single IP address and a local director selects the server from among the plurality of servers which is to receive the connection. Thus, the DNS server is not relied upon to distribute connections, and the connection distribution scheme is not avoided when DNS is bypassed. In one embodiment, a session distribution scheme is implemented such that connections are distributed to the server in the group of servers which has the fewest connections of the group. In other embodiments, other session distribution schemes which route connections based on the predicted response times of the servers or according to a round robin scheme are used.Type: GrantFiled: September 12, 2001Date of Patent: December 5, 2006Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey, Peter A. Tenereillo
-
Patent number: 7039008Abstract: A system and method are disclosed for maintaining the state of a virtual connection supported by an active connection manager on a standby connection manager. The method includes configuring the standby connection manager to include a physical machine object that stores a physical IP address of a physical machine that is available to the active connection manager and a virtual machine object that stores a virtual IP address of a virtual machine that is implemented on the connection manager. A replication packet is received at the standby connection manager from the active connection manager wherein the replication packet includes a foreign IP address, the virtual IP address and the physical IP address. A standby connection object is stored in the connection manager. The standby connection object includes the foreign IP address, the virtual IP address and the physical IP address from the replication packet on the standby connection manager.Type: GrantFiled: September 12, 2001Date of Patent: May 2, 2006Assignee: Cisco Technology, Inc.Inventors: Richard A. Howes, Edward C. Kersey, Bruce F. Wong, James A. Jordan, William M. Leblanc, Andrew L. Foss
-
Patent number: 6606315Abstract: A method of obtaining instructions for routing a packet is described that includes receiving a packet having a packet flow identifier that includes a packet source IP address, a packet destination IP address, a packet source port, and a packet destination port and checking whether the packet flow identifier matches a stored instruction. If the packet flow identifier does not match a stored instruction, whether the packet flow identifier matches a stored criteria is checked and if the packet matches a stored criteria, the packet is forwarded to a service manager.Type: GrantFiled: July 2, 1999Date of Patent: August 12, 2003Assignee: Cisco Technology, Inc.Inventors: Mark Albert, Richard A. Howes, James A. Jordan, Edward C. Kersey, Louis F. Menditto, Chris O'Rourke, Pranav Kumar Tiwari, Tzu-Ming Tsang
-
Patent number: 6445704Abstract: A system and method are disclosed for virtualizing locally initiated outbound connections from a physical machine used to implement a virtual machine. The method includes providing a virtual machine object having a virtual IP address that corresponds to the virtual machine. Inbound connections directed to the virtual machine are handled by the physical machine having a physical machine IP address. A static physical machine object is also provided. The static physical machine object contains the virtual IP address and the physical machine IP address. When a SYN packet is intercepted for an outbound connection having a SYN packet source IP address that corresponds to the physical machine IP address and a packet destination address that corresponds to a foreign IP address, it is determined whether the packet source IP address matches the physical machine IP address.Type: GrantFiled: June 30, 1998Date of Patent: September 3, 2002Assignee: Cisco Technology, Inc.Inventors: Richard A. Howes, Edward C. Kersey
-
Patent number: 6366558Abstract: A system and method are disclosed for maintaining the state of a virtual connection supported by an active connection manager on a standby connection manager. The method includes configuring the standby connection manager to include a physical machine object that stores a physical IP address of a physical machine that is available to the active connection manager and a virtual machine object that stores a virtual IP address of a virtual machine that is implemented on the connection manager. A replication packet is received at the standby connection manager from the active connection manager wherein the replication packet includes a foreign IP address, the virtual IP address and the physical IP address. A standby connection object is stored in the connection manager. The standby connection object includes the foreign IP address, the virtual IP address and the physical IP address from the replication packet on the standby connection manager.Type: GrantFiled: June 30, 1998Date of Patent: April 2, 2002Assignee: Cisco Technology, Inc.Inventors: Richard A. Howes, Edward C. Kersey, Bruce F. Wong, James A. Jordan, William M. Leblanc, Andrew L. Foss
-
Patent number: 6324177Abstract: A system and method are disclosed for assigning an incoming connection to a server. The method includes defining a client specific virtual machine object instance that is associated with a designated client IP address. An incoming packet is received that is associated with a new connection. The incoming packet has a packet source IP address, a packet source port number, a packet destination IP address, and a packet destination port number. A client specific virtual machine object instance is selected that is associated with the designated client IP address when the packet source IP address matches the designated client IP address.Type: GrantFiled: June 30, 1998Date of Patent: November 27, 2001Assignee: Cisco TechnologyInventors: Richard A. Howes, Edward C. Kersey
-
Patent number: 6317775Abstract: Disclosed is a system and method for distributing connections among a plurality of servers at an Internet site. All connections are made to a single IP address and a local director selects the server from among the plurality of servers which is to receive the connection. Thus, the DNS server is not relied upon to distribute connections, and the connection distribution scheme is not avoided when DNS is bypassed. In one embodiment, a session distribution scheme is implemented such that connections are distributed to the server in the group of servers which has the fewest connections of the group. In other embodiments, other session distribution schemes which route connections based on the predicted response times of the servers or according to a round robin scheme are used.Type: GrantFiled: January 25, 1999Date of Patent: November 13, 2001Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey, Peter A. Tenereillo
-
Patent number: 6298063Abstract: A system and method are disclosed for redirecting a connection from a first server having a first server IP address. Incoming SYN packets sent from a client are intercepted. The SYN packets have a destination IP address corresponding to the connection and the SYN packets are sent from the client for the purpose of establishing the connection, which is supported by the first server. The number of incoming SYN packets sent from the client to the first server is monitored and it is determined whether the number of unanswered SYN packets sent by the client to the first server exceeds a ditched connection threshold number of unanswered SYN packets. The destination IP address of intercepted incoming SYN packets is changed for the connection received after determining that the number of unanswered SYN requests sent by the client to the first server exceeds a ditched connection threshold number of unanswered SYN requests to the destination IP address of a second server.Type: GrantFiled: March 15, 2000Date of Patent: October 2, 2001Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey
-
Patent number: 6295557Abstract: A system and method are disclosed for simulating a plurality of TCP connections directed toward an Internet site under test. The method includes activating a producer thread process. The producer thread process includes randomly determining an IP address and requesting a TCP layer process to make a TCP connection to the randomly determined IP address. The producer thread process does not block or wait for the TCP connection to be established. A consumer thread process is activated upon the occurrence of an event on the TCP connection. The consumer thread process includes retrieving information from the TCP connection and recording statistics related to the information.Type: GrantFiled: June 30, 1998Date of Patent: September 25, 2001Assignee: Cisco Technology, Inc.Inventors: Andrew L. Foss, Richard A. Howes, William M. Leblanc, Edward C. Kersey
-
Patent number: 6104717Abstract: A system and method are disclosed for redirecting a connection from a first server having a first server IP address. Incoming SYN packets sent from a client are intercepted. The SYN packets have a destination IP address corresponding to the connection and the SYN packets are sent from the client for the purpose of establishing the connection, which is supported by the first server. The number of incoming SYN packets sent from the client to the first server is monitored and it is determined whether the number of unanswered SYN packets sent by the client to the first server exceeds a ditched connection threshold number of unanswered SYN packets. The destination IP address of intercepted incoming SYN packets is changed for the connection received after determining that the number of unanswered SYN requests sent by the client to the first server exceeds a ditched connection threshold number of unanswered SYN requests to the destination IP address of a second server.Type: GrantFiled: May 2, 1997Date of Patent: August 15, 2000Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey
-
Patent number: 6061349Abstract: Disclosed is a system and method for handling a plurality of connection requests made for a plurality of virtual machines with a single physical machine. A system and method are disclosed for distributing virtual connections among a plurality of physical machines some or all of which are configured to handle connections for more than one virtual machine. In one embodiment, a packet translation system for handling connections from clients on an external network to a plurality of IP addresses with a server having a server IP address and a server port number includes a client interface to the external network. The client interface is operative to receive and send packets to and from a remote client. A server interface is operative to receive and send packets to and from the server and the server is operative to establish a connection with the remote client.Type: GrantFiled: May 2, 1997Date of Patent: May 9, 2000Assignee: Cisco Technology, Inc.Inventors: Brantley W. Coile, Richard A. Howes, Edward C. Kersey