Patents by Inventor Flemming S. Andreasen

Flemming S. Andreasen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12706923
    Abstract: In one embodiment, a method includes classifying a first encrypted data flow in accordance with a classification. Classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow. The method further includes generating an indicator that indicates a confidence in the classification of the first encrypted data flow. The method further includes generating a determination of whether the first encrypted data flow comprises malware. The method further includes classifying one or more subsequent encrypted data flows in accordance with the classification. Classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
    Type: Grant
    Filed: December 20, 2023
    Date of Patent: August 11, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Robert Edgar Barton, Flemming S. Andreasen, Barry Qi Yuan, Bhavik Pradeep Shah, Indermeet Singh Gandhi
  • Publication number: 20260194887
    Abstract: In one embodiment, a device associates available 5G functions with contextual information, wherein the contextual information maps each of the available 5G functions to a segment identifier of a security model topology for a segmented network within which that available 5G function is deployed. The device receives a request from a user equipment endpoint to communicate via the segmented network. The device selects a particular user plane function from among the available 5G functions for use by the user equipment endpoint based in part on the segment identifier of the security model topology mapped to the particular user plane function. The device causes the user equipment endpoint to communicate via the segmented network using the particular user plane function.
    Type: Application
    Filed: March 4, 2026
    Publication date: July 9, 2026
    Inventors: Flemming S. Andreasen, Timothy P. Stammers, Robert Edgar Barton
  • Publication number: 20260129067
    Abstract: Techniques are described herein for determining and mitigating a risk to an organization associated with a security threat. In embodiments, such techniques may be performed by an access control device and may comprise receiving information about a security threat, identifying one or more components susceptible to the security threat, determining a number of software applications associated with the one or more components, and determining, based on usage metrics stored in relation to the number of software applications, a severity associated with each of the number of software applications. The techniques may further comprise determining at least one mitigation technique associated with a software application having the highest severity in relation to the security threat and causing the at least one mitigation technique to be implemented.
    Type: Application
    Filed: January 5, 2026
    Publication date: May 7, 2026
    Inventors: Nancy Patricia Cam-Winget, Robert Edgar Barton, Edward Albert Warnicke, Flemming S. Andreasen
  • Publication number: 20250274489
    Abstract: This disclosure describes techniques for distributing security service by performing security policy-based routing among network devices. The techniques include determining a security function to be applied to a packet of a data traffic flow. The security function may be determined based on a security policy and an intended destination of the packet. The techniques may also include determining whether a network device is capable of performing the security function. A route for the packet to the destination may be determined based on whether the network device is capable of performing the security function. As such, distributing security service techniques may improve efficiency in data traffic routing, and may reduce cost and/or prevent redundancy in security service application.
    Type: Application
    Filed: February 23, 2024
    Publication date: August 28, 2025
    Inventors: Flemming S. Andreasen, Robert Edgar Barton, Saravanan Radhakrishnan
  • Publication number: 20250211598
    Abstract: In one embodiment, a method includes classifying a first encrypted data flow in accordance with a classification. Classifying the first encrypted data flow is based on characteristic information associated with the first encrypted data flow. The method further includes generating an indicator that indicates a confidence in the classification of the first encrypted data flow. The method further includes generating a determination of whether the first encrypted data flow comprises malware. The method further includes classifying one or more subsequent encrypted data flows in accordance with the classification. Classifying the one or more subsequent encrypted data flows is based on the determination of whether the first encrypted data flow comprises malware.
    Type: Application
    Filed: December 20, 2023
    Publication date: June 26, 2025
    Inventors: Robert Edgar Barton, Flemming S. Andreasen, Barry Qi Yuan, Bhavik Pradeep Shah, Indermeet Singh Gandhi
  • Publication number: 20240388595
    Abstract: Techniques are described herein for determining and mitigating a risk to an organization associated with a security threat. In embodiments, such techniques may be performed by an access control device and may comprise receiving information about a security threat, identifying one or more components that are susceptible to the security threat, determining, based on a software bill of materials, a number of software applications associated with the one or more components, determining, based on usage metrics stored in relation to the number of software applications in relation to an organization, a risk value associated with the organization, and providing the risk value to at least one second electronic device.
    Type: Application
    Filed: May 16, 2023
    Publication date: November 21, 2024
    Inventors: Nancy Patricia Cam-Winget, Robert Edgar Barton, Edward Albert Warnicke, Flemming S. Andreasen
  • Publication number: 20240364687
    Abstract: This disclosure describes techniques for validating a network device based on an operational context of the network device. The techniques may include receiving, via an intercepting node, a DNS query from a querying device. The techniques may include extracting the metadata from the DNS query. Based at least in part on verifying a signature of the metadata, the techniques may include extracting a location code from the metadata. Based at least in part on comparing the location code to an expected location of the intercepting node, the techniques may include sending a response to the querying device indicating a contextual validation of the querying device.
    Type: Application
    Filed: April 25, 2023
    Publication date: October 31, 2024
    Inventors: Robert Edgar Barton, David John Zacks, Thomas Szigeti, Flemming S. Andreasen
  • Patent number: 10588044
    Abstract: A method is provided in one example embodiment and includes receiving a data packet transported on a backhaul link at a first network element; de-capsulating the data packet; identifying whether the data packet is an upstream data packet; identifying whether the data packet matches an internet protocol (IP) access control list (ACL) or a tunnel endpoint identifier; and offloading the data packet from the backhaul link. In more specific embodiment, the method can include identifying that the data packet does not match the IP ACL or the tunnel endpoint identifier; and communicating the data packet to a second network element. In other examples, the method can include identifying that the data packet is a downstream data packet; identifying a service to be performed for the data packet that cannot be performed at the first network element; and communicating the data packet to a second network element.
    Type: Grant
    Filed: May 14, 2018
    Date of Patent: March 10, 2020
    Assignee: Cisco Technology, Inc.
    Inventors: Flemming S. Andreasen, Kent K. Leung, Michel Khouderchah, Jayaraman R. Iyer, Timothy P. Stammers
  • Patent number: 10111060
    Abstract: A system is disclosed for measuring data utilization attributable to use by an application being executed on a mobile device. The system has a server operable to register the application and transmit information to establish a connection between the application and a proxy server. The system also has a proxy server operable to establish a first connection with the application, receive direction to establish a second connection with a target endpoint, establish the second connection between the proxy server and the target endpoint, pass data between the target endpoint and the application using the established connections, and measure the amount of data passed between the target endpoint and the application.
    Type: Grant
    Filed: June 12, 2013
    Date of Patent: October 23, 2018
    Assignee: Cisco Tecnology, Inc.
    Inventors: Kent K. Leung, Jayaraman R. Iyer, Flemming S. Andreasen
  • Publication number: 20180262942
    Abstract: A method is provided in one example embodiment and includes receiving a data packet transported on a backhaul link at a first network element; de-capsulating the data packet; identifying whether the data packet is an upstream data packet; identifying whether the data packet matches an internet protocol (IP) access control list (ACL) or a tunnel endpoint identifier; and offloading the data packet from the backhaul link. In more specific embodiment, the method can include identifying that the data packet does not match the IP ACL or the tunnel endpoint identifier; and communicating the data packet to a second network element. In other examples, the method can include identifying that the data packet is a downstream data packet; identifying a service to be performed for the data packet that cannot be performed at the first network element; and communicating the data packet to a second network element.
    Type: Application
    Filed: May 14, 2018
    Publication date: September 13, 2018
    Inventors: Flemming S. ANDREASEN, Kent K. LEUNG, Michel KHOUDERCHAH, Jayaraman R. IYER, Timothy P. STAMMERS
  • Patent number: 10063556
    Abstract: A method is provided and may include receiving a request for a network content delivery service from an access device; directing the access device to a network service provider for authentication for the network content delivery service; receiving a network authorization token from the access device, where the network authorization token is associated with the access device; obtaining a network access token from the network service provider; and binding the network access token to a content access token.
    Type: Grant
    Filed: August 4, 2016
    Date of Patent: August 28, 2018
    Assignee: Cisco Technology, Inc.
    Inventors: Kent K. Leung, Jayaraman R. Iyer, Bruce A. Thompson, Flemming S. Andreasen
  • Patent number: 9973961
    Abstract: A method is provided in one example embodiment and includes receiving a data packet transported on a backhaul link at a first network element; de-capsulating the data packet; identifying whether the data packet is an upstream data packet; identifying whether the data packet matches an internet protocol (IP) access control list (ACL) or a tunnel endpoint identifier; and offloading the data packet from the backhaul link. In more specific embodiment, the method can include identifying that the data packet does not match the IP ACL or the tunnel endpoint identifier; and communicating the data packet to a second network element. In other examples, the method can include identifying that the data packet is a downstream data packet; identifying a service to be performed for the data packet that cannot be performed at the first network element; and communicating the data packet to a second network element.
    Type: Grant
    Filed: April 10, 2015
    Date of Patent: May 15, 2018
    Assignee: Cisco Technology, Inc.
    Inventors: Flemming S. Andreasen, Kent K. Leung, Michel Khouderchah, Jayaraman R. Iyer, Timothy P. Stammers
  • Patent number: 9960928
    Abstract: A method is provided in one example embodiment and includes establishing a connection between a client and a messaging fabric of a conductor element associated with a video system; creating a plurality of nodes for system management events; and receiving a subscription request for a particular one of the system management events. The particular subscription request and system management event is authenticated and authorized by use of an identifier associated with the particular subscription request and system management event.
    Type: Grant
    Filed: July 6, 2012
    Date of Patent: May 1, 2018
    Assignee: Cisco Technology, Inc.
    Inventors: Nick George Pope, Flemming S. Andreasen, Qi Wang, Jerry Liansuo Li
  • Patent number: 9854000
    Abstract: In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of malicious software.
    Type: Grant
    Filed: November 6, 2014
    Date of Patent: December 26, 2017
    Assignee: Cisco Technology, Inc.
    Inventors: Daniel G. Wing, Flemming S. Andreasen, Kent K. Leung
  • Publication number: 20170034175
    Abstract: A method is provided and may include receiving a request for a network content delivery service from an access device; directing the access device to a network service provider for authentication for the network content delivery service; receiving a network authorization token from the access device, where the network authorization token is associated with the access device; obtaining a network access token from the network service provider; and binding the network access token to a content access token.
    Type: Application
    Filed: August 4, 2016
    Publication date: February 2, 2017
    Applicant: CISCO TECHNOLOGY, INC.
    Inventors: Kent K. Leung, Jayaraman R. Iyer, Bruce A. Thompson, Flemming S. Andreasen
  • Patent number: 9413748
    Abstract: A method is provided and may include receiving a request for a network content delivery service from an access device; directing the access device to a network service provider for authentication for the network content delivery service; receiving a network authorization token from the access device, where the network authorization token is associated with the access device; obtaining a network access token from the network service provider; and binding the network access token to a content access token.
    Type: Grant
    Filed: March 15, 2013
    Date of Patent: August 9, 2016
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Kent K. Leung, Jayaraman R. Iyer, Bruce A. Thompson, Flemming S. Andreasen
  • Patent number: 9397940
    Abstract: An example method is provided and includes receiving a packet associated with a flow, determining a tunnel identifier for the flow, and determining a flow identifier for the flow. The method includes associating the flow identifier and the tunnel identifier to an Internet protocol (IP) address to generate a binding to be used for a network address and port translation (NAPT). In other embodiments, a routing decision is executed based on the binding between the identifiers and the IP address. The flow identifier can be a context identifier (CID), and the tunnel identifier can be a softwire tunnel ID. In yet other embodiments, the packet can be tagged as part of an encapsulation operation, which includes providing information about a network location at which the network address and port translation is to be executed.
    Type: Grant
    Filed: February 14, 2014
    Date of Patent: July 19, 2016
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Srinath Gundavelli, Frank Brockners, Mark Grayson, Kent K. Leung, Flemming S. Andreasen
  • Patent number: 9374619
    Abstract: A method is provided in one example embodiment and includes establishing a connection between a first client and a messaging fabric of a conductor element associated with a video system; receiving a request to perform a companion service with a second client; authenticating the first client via a client directory based on an identifier associated with the first client; receiving a pair message from the first client for the second client; and verifying whether the two clients can be paired in order to perform the companion service. Companion service commands can be authorized/policy checked and resulting commands on the second client may appear as-if they had been triggered locally.
    Type: Grant
    Filed: January 28, 2014
    Date of Patent: June 21, 2016
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Flemming S. Andreasen, Gil C. Cruz, Nick George Pope
  • Publication number: 20160134646
    Abstract: In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of malicious software.
    Type: Application
    Filed: November 6, 2014
    Publication date: May 12, 2016
    Applicant: Cisco Technology, Inc.
    Inventors: Daniel G. Wing, Flemming S. Andreasen, Kent K. Leung
  • Patent number: 9215588
    Abstract: An example method includes receiving a message related to a bearer or an Internet Protocol (IP) flow, the message includes an extension indicating whether an Internet Protocol security (IPsec) feature is designated for the bearer or the IP flow. The method further includes mapping a communication flow to the bearer or the IP flow, and applying the IPsec feature to the bearer or the IP flow. In other embodiments, the method can include communicating the extension to a next destination, and updating a security policy to indicate that the bearer or the IP flow is designated for the IPsec feature. In yet other embodiments, an Internet Key Exchange (IKE) is used to establish a security association for a serving gateway associated with the communication flow. The extension is provided at an IP flow level or at a bearer level such that network traffic is designated for the IPsec feature.
    Type: Grant
    Filed: April 30, 2010
    Date of Patent: December 15, 2015
    Assignee: CISCO TECHNOLOGY, INC.
    Inventor: Flemming S. Andreasen