Patents by Inventor Frank Kastenholz

Frank Kastenholz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11856027
    Abstract: A secure communication system enabling secure transport of information is disclosed. The system comprises a secure network with one or more packet processing units connected by links through an internal communication system. The secure network transports packets of information between credentialed and authenticated agents. Each packet is associated with a visa issued by a visa service. The visa specifies the procedures governing the processing of the packet by the packet processing units as it is transported along a compliant flow, between agents thorough the network, according to a set of policies specified in a network configuration. Packet processing units include docks and forwarders. Adaptors serving the agents communicate with the network through tie-ins to docks. The system also includes and admin service, accessible to one more admins, that facilitates configuration and management of the network.
    Type: Grant
    Filed: November 6, 2020
    Date of Patent: December 26, 2023
    Assignee: APPLIED INVENTION, LLC
    Inventors: W. Daniel Hillis, David C. Douglas, Mathias Kolehmainen, Steven Willis, Frank Kastenholz, Michael Dubno
  • Publication number: 20230171228
    Abstract: Methods, devices, and system related to secure communication systems are disclosed. In one example aspect, a secure communication system enabling secure transport of information includes a secure network comprising one or more nodes communicatively coupled by an internal communication system and a set of policies. The secure network internally transports the information in the form of internal packets. Each of the internal packets is associated with a visa that references the policies. A node among said one or more nodes transmits an internal packet of said information only if allowed by said policies as referenced by said visa.
    Type: Application
    Filed: January 27, 2023
    Publication date: June 1, 2023
    Inventors: W. Daniel Hillis, David C. Douglas, Mathias Kolehmainen, Steven Willis, Frank Kastenholz, Michael Dubno
  • Publication number: 20220368688
    Abstract: A secure communication system enabling secure transport of information is disclosed. The system comprises a secure network with one or more packet processing units connected by links through an internal communication system. The secure network transports packets of information between credentialed and authenticated agents. Each packet is associated with a visa issued by a visa service. The visa specifies the procedures governing the processing of the packet by the packet processing units as it is transported along a compliant flow, between agents thorough the network, according to a set of policies specified in a network configuration. Packet processing units include docks and forwarders. Adaptors serving the agents communicate with the network through tie-ins to docks. The system also includes and admin service, accessible to one more admins, that facilitates configuration and management of the network.
    Type: Application
    Filed: July 22, 2022
    Publication date: November 17, 2022
    Inventors: W. Daniel HILLIS, David C. DOUGLAS, Mathias KOLEHMAINEN, Steven WILLIS, Frank KASTENHOLZ, Michael DUBNO
  • Publication number: 20220232000
    Abstract: A secure communication system enabling secure transport of information is disclosed. The system comprises a secure network with one or more packet processing units connected by links through an internal communication system. The secure network transports packets of information between credentialed and authenticated agents. Each packet is associated with a visa issued by a visa service. The visa specifies the procedures governing the processing of the packet by the packet processing units as it is transported along a compliant flow, between agents thorough the network, according to a set of policies specified in a network configuration. Packet processing units include docks and forwarders. Adaptors serving the agents communicate with the network through tie-ins to docks. The system also includes and admin service, accessible to one more admins, that facilitates configuration and management of the network.
    Type: Application
    Filed: April 5, 2022
    Publication date: July 21, 2022
    Inventors: W. Daniel HILLIS, David C. DOUGLAS, Mathias KOLEHMAINEN, Steven WILLIS, Frank KASTENHOLZ, Michael DUBNO
  • Publication number: 20210058369
    Abstract: A secure communication system enabling secure transport of information is disclosed. The system comprises a secure network with one or more packet processing units connected by links through an internal communication system. The secure network transports packets of information between credentialed and authenticated agents. Each packet is associated with a visa issued by a visa service. The visa specifies the procedures governing the processing of the packet by the packet processing units as it is transported along a compliant flow, between agents thorough the network, according to a set of policies specified in a network configuration. Packet processing units include docks and forwarders. Adaptors serving the agents communicate with the network through tie-ins to docks. The system also includes and admin service, accessible to one more admins, that facilitates configuration and management of the network.
    Type: Application
    Filed: November 6, 2020
    Publication date: February 25, 2021
    Inventors: W. Daniel HILLIS, David C. DOUGLAS, Mathias KOLEHMAINEN, Steven WILLIS, Frank KASTENHOLZ, Michael DUBNO
  • Patent number: 9077777
    Abstract: A forwarding node decapsulates and encapsulates data. The decapsulation may be performed using pattern matching techniques and the encapsulation may be performed using pattern insertion techniques. The decapsulation and encapsulation are preferably performed by hardware devices such as application specific integrated circuits (ASICs) to enhance the speed of such operations. The decapsulation and encapsulation may be independent of each other and performed on a per virtual circuit basis.
    Type: Grant
    Filed: April 29, 2013
    Date of Patent: July 7, 2015
    Assignee: Juniper Networks, Inc.
    Inventors: Steven R Willis, Gregg F Bromley, Eric S Crawley, Frank Kastenholz
  • Publication number: 20130238810
    Abstract: A forwarding node decapsulates and encapsulates data. The decapsulation may be performed using pattern matching techniques and the encapsulation may be performed using pattern insertion techniques. The decapsulation and encapsulation are preferably performed by hardware devices such as application specific integrated circuits (ASICs) to enhance the speed of such operations. The decapsulation and encapsulation may be independent of each other and performed on a per virtual circuit basis.
    Type: Application
    Filed: April 29, 2013
    Publication date: September 12, 2013
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Steven R. WILLIS, Gregg F. BROMLEY, Eric S. CRAWLEY, Frank KASTENHOLZ
  • Patent number: 8468590
    Abstract: A network device coordinates with other devices in a network to create a distributed filtering system. The device detects an attack in the network, such as a distributed denial of service attack, and forwards attack information to the other devices. The devices may categorize data into one or more groups and rate limit the amount of data being forwarded based on rate limits for the particular categories. The rate limits may also be updated based on the network conditions. The rate limits may further be used to guarantee bandwidth for certain categories of data.
    Type: Grant
    Filed: February 25, 2011
    Date of Patent: June 18, 2013
    Assignee: Juniper Networks, Inc.
    Inventors: Ross W Callon, Frank Kastenholz
  • Patent number: 8432921
    Abstract: A forwarding node decapsulates and encapsulates data. The decapsulation may be performed using pattern matching techniques and the encapsulation may be performed using pattern insertion techniques. The decapsulation and encapsulation are preferably performed by hardware devices such as application specific integrated circuits (ASICs) to enhance the speed of such operations. The decapsulation and encapsulation may be independent of each other and performed on a per virtual circuit basis.
    Type: Grant
    Filed: August 26, 2010
    Date of Patent: April 30, 2013
    Assignee: Juniper Networks, Inc.
    Inventors: Steven R. Willis, Gregg F. Bromley, Eric S. Crawley, Frank Kastenholz
  • Patent number: 8306028
    Abstract: An interconnect network for operation within communication node, wherein the interconnect network may have features including the ability to transfer a variety of communication protocols, scalable bandwidth and reduced down-time. According to one embodiment of the invention, the communication node includes a plurality of I/O channels for coupling information into and out of the node, and the interconnect network includes at least one local interconnect module having local transfer elements for transferring information between the plurality of I/O channels; and scaling elements for expanding the interconnect network to include additional local interconnect modules, such that information can be transferred between the local interconnect modules included in the interconnect network.
    Type: Grant
    Filed: September 18, 2009
    Date of Patent: November 6, 2012
    Assignee: Juniper Networks, Inc.
    Inventors: Frank Kastenholz, Tom Westberg, Steven R. Willis
  • Publication number: 20110197274
    Abstract: A network device coordinates with other devices in a network to create a distributed filtering system. The device detects an attack in the network, such as a distributed denial of service attack, and forwards attack information to the other devices. The devices may categorize data into one or more groups and rate limit the amount of data being forwarded based on rate limits for the particular categories. The rate limits may also be updated based on the network conditions. The rate limits may further be used to guarantee bandwidth for certain categories of data.
    Type: Application
    Filed: February 25, 2011
    Publication date: August 11, 2011
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Ross W. CALLON, Frank Kastenholz
  • Patent number: 7921460
    Abstract: A network device coordinates with other devices in a network to create a distributed filtering system. The device detects an attack in the network, such as a distributed denial of service attack, and forwards attack information to the other devices. The devices may categorize data into one or more groups and rate limit the amount of data being forwarded based on rate limits for the particular categories. The rate limits may also be updated based on the network conditions. The rate limits may further be used to guarantee bandwidth for certain categories of data.
    Type: Grant
    Filed: May 15, 2008
    Date of Patent: April 5, 2011
    Assignee: Juniper Networks, Inc.
    Inventors: Ross W. Callon, Frank Kastenholz
  • Publication number: 20100322242
    Abstract: A forwarding node decapsulates and encapsulates data. The decapsulation may be performed using pattern matching techniques and the encapsulation may be performed using pattern insertion techniques. The decapsulation and encapsulation are preferably performed by hardware devices such as application specific integrated circuits (ASICs) to enhance the speed of such operations. The decapsulation and encapsulation may be independent of each other and performed on a per virtual circuit basis.
    Type: Application
    Filed: August 26, 2010
    Publication date: December 23, 2010
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Steven R. WILLIS, Gregg F. BROMLEY, Eric S. CRAWLEY, Frank KASTENHOLZ
  • Patent number: 7809015
    Abstract: A network device bundles packet over synchronous optical network (POS) data stream and asynchronous transfer mode (ATM) data stream into a synchronous optical network (SONET) data stream. The POS data stream and the ATM data stream are virtual channels or tributaries of the SONET data stream. The SONET data stream may be transmitted over a single optical fiber.
    Type: Grant
    Filed: September 22, 2003
    Date of Patent: October 5, 2010
    Assignee: Juniper Networks, Inc.
    Inventors: Steven R. Willis, Gregg F. Bromley, Eric S. Crawley, Frank Kastenholz
  • Publication number: 20100067523
    Abstract: An interconnect network for operation within communication node, wherein the interconnect network may have features including the ability to transfer a variety of communication protocols, scalable bandwidth and reduced down-time. According to one embodiment of the invention, the communication node includes a plurality of I/O channels for coupling information into and out of the node, and the interconnect network includes at least one local interconnect module having local transfer elements for transferring information between the plurality of I/O channels; and scaling elements for expanding the interconnect network to include additional local interconnect modules, such that information can be transferred between the local interconnect modules included in the interconnect network.
    Type: Application
    Filed: September 18, 2009
    Publication date: March 18, 2010
    Applicant: JUNIPER NETWORKS, INC.
    Inventors: Frank KASTENHOLZ, Tom WESTBERG, Steven R. WILLIS
  • Patent number: 7613173
    Abstract: An interconnect network for operation within communication node, wherein the interconnect network may have features including the ability to transfer a variety of communication protocols, scalable bandwidth and reduced down-time. According to one embodiment of the invention, the communication node includes a plurality of I/O channels for coupling information into and out of the node, and the interconnect network includes at least one local interconnect module having local transfer elements for transferring information between the plurality of I/O channels; and scaling elements for expanding the interconnect network to include additional local interconnect modules, such that information can be transferred between the local interconnect modules included in the interconnect network.
    Type: Grant
    Filed: September 14, 2005
    Date of Patent: November 3, 2009
    Assignee: Juniper Networks, Inc.
    Inventors: Frank Kastenholz, Tom Westberg, Steven R. Willis
  • Patent number: 7389537
    Abstract: A network device coordinates with other devices in a network to create a distributed filtering system. The device detects an attack in the network, such as a distributed denial of service attack, and forwards attack information to the other devices. The devices may categorize data into one or more groups and rate limit the amount of data being forwarded based on rate limits for the particular categories. The rate limits may also be updated based on the network conditions. The rate limits may further be used to guarantee bandwidth for certain categories of data.
    Type: Grant
    Filed: May 8, 2003
    Date of Patent: June 17, 2008
    Assignee: Juniper Networks, Inc.
    Inventors: Ross W. Callon, Frank Kastenholz
  • Publication number: 20060007946
    Abstract: An interconnect network for operation within communication node, wherein the interconnect network may have features including the ability to transfer a variety of communication protocols, scalable bandwidth and reduced down-time. According to one embodiment of the invention, the communication node includes a plurality of I/O channels for coupling information into and out of the node, and the interconnect network includes at least one local interconnect module having local transfer elements for transferring information between the plurality of I/O channels; and scaling elements for expanding the interconnect network to include additional local interconnect modules, such that information can be transferred between the local interconnect modules included in the interconnect network.
    Type: Application
    Filed: September 14, 2005
    Publication date: January 12, 2006
    Inventors: Frank Kastenholz, Tom Westberg, Steven Willis
  • Patent number: 6980543
    Abstract: An interconnect network for operation within communication node, wherein the interconnect network may have features including the ability to transfer a variety of communication protocols, scalable bandwidth and reduced down-time. According to one embodiment of the invention, the communication node includes a plurality of I/O channels for coupling information into and out of the node, and the interconnect network includes at least one local interconnect module having local transfer elements for transferring information between the plurality of I/O channels; and scaling elements for expanding the interconnect network to include additional local interconnect modules, such that information can be transferred between the local interconnect modules included in the interconnect network.
    Type: Grant
    Filed: June 18, 1999
    Date of Patent: December 27, 2005
    Assignee: Juniper Networks, Inc.
    Inventors: Frank Kastenholz, Tom Westberg, Steven R. Willis
  • Patent number: 6975631
    Abstract: A switch/router contains intelligence for more quickly determining a next hop for an network layer packet. A network forwarding lookup table or array structure is configured so as to minimize the number of memory accesses required. This results in a decrease in time due to memory access and a decrease in computational overhead due to the memory accesses. In one embodiment, a first forwarding lookup is indexed by the first 16 bits of a destination address. A second forwarding lookup is indexed by the subsequent 8 bits of the destination address, and a final third forwarding lookup is indexed by the last 8 bits of the destination address. Each entry within a forwarding lookup contains either direction as to how properly forward the packet or reference to a next subsequent forwarding lookup.
    Type: Grant
    Filed: January 25, 1999
    Date of Patent: December 13, 2005
    Assignee: Juniper Networks, Inc.
    Inventor: Frank Kastenholz