Patents by Inventor Geoffrey Huang
Geoffrey Huang has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 9391869Abstract: A system includes a storage device to store information associated with virtual nodes that correspond to network nodes. The system also includes a server to install a virtual node that corresponds to one of the network nodes, based on the information associated with the virtual node, where installing the virtual node includes creating a logical interface via which traffic is to be sent to, or received from, other virtual nodes; start the virtual node to create an operating virtual node based on a copy of an operating system that is run on the network node, where starting the virtual node causes the operational virtual node to execute the copy of the operating system; and cause the operating virtual node to communicate with a virtual network that includes the virtual nodes, where causing the operating virtual node to communicate with the virtual network enables the operating virtual node to receive or forward traffic associated with the virtual network.Type: GrantFiled: February 25, 2014Date of Patent: July 12, 2016Assignee: Juniper Networks, Inc.Inventors: Daniel Kharitonov, Colin Constable, Geoffrey Huang, Joel Obstfeld
-
Publication number: 20140177471Abstract: A system includes a storage device to store information associated with virtual nodes that correspond to network nodes. The system also includes a server to install a virtual node that corresponds to one of the network nodes, based on the information associated with the virtual node, where installing the virtual node includes creating a logical interface via which traffic is to be sent to, or received from, other virtual nodes; start the virtual node to create an operating virtual node based on a copy of an operating system that is run on the network node, where starting the virtual node causes the operational virtual node to execute the copy of the operating system; and cause the operating virtual node to communicate with a virtual network that includes the virtual nodes, where causing the operating virtual node to communicate with the virtual network enables the operating virtual node to receive or forward traffic associated with the virtual network.Type: ApplicationFiled: February 25, 2014Publication date: June 26, 2014Applicant: Juniper Networks, Inc.Inventors: Daniel KHARITONOV, Colin Constable, Geoffrey Huang, Joel Obstfeld
-
Patent number: 8671176Abstract: A system includes a storage device to store information associated with virtual nodes that correspond to network nodes. The system also includes a server to install a virtual node that corresponds to one of the network nodes, based on the information associated with the virtual node, where installing the virtual node includes creating a logical interface for sending traffic to, or receiving traffic from, other virtual nodes; start the virtual node to create an operating virtual node based on a copy of an operating system that runs on the network node, where starting the virtual node causes the operational virtual node to execute the copy of the operating system; and cause the operating virtual node to communicate with a virtual network, that includes the other virtual nodes, to allow the operating virtual node to receive or forward traffic associated with the virtual network.Type: GrantFiled: September 29, 2011Date of Patent: March 11, 2014Assignee: Juniper Networks, Inc.Inventors: Daniel Kharitonov, Colin Constable, Geoffrey Huang, Joel Obstfeld
-
Patent number: 8261318Abstract: Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.Type: GrantFiled: September 22, 2010Date of Patent: September 4, 2012Assignee: Cisco Technology, Inc.Inventors: Geoffrey Huang, Jan Vilhuber
-
Publication number: 20110016509Abstract: Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.Type: ApplicationFiled: September 22, 2010Publication date: January 20, 2011Inventors: Geoffrey HUANG, Jan VILHUBER
-
Patent number: 7849495Abstract: Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.Type: GrantFiled: August 22, 2002Date of Patent: December 7, 2010Assignee: Cisco Technology, Inc.Inventors: Geoffrey Huang, Jan Vilhuber
-
Patent number: 7562384Abstract: Resolving information associated with a network device includes receiving a request for first information associated with the network device. The request includes second information associated with the device, such as identification information. Based on the second information, an entry that includes the first information in association with the second information is located in a security association database. For example, an entry that includes the information association is located in a Security Association Database (SAD) of an IPsec endpoint device. The first information is read from the entry and a response to the request is based on this first information. The association between the first and the second information that is stored in the relevant database may be based on an identification authentication mechanism.Type: GrantFiled: March 7, 2003Date of Patent: July 14, 2009Assignee: Cisco Technology, Inc.Inventor: Geoffrey Huang
-
Patent number: 7421578Abstract: A method performed by a first computer node for selecting a leader node to provide service to a plurality of other nodes in a multicast group, wherein each of the nodes communicates using multicast messages, comprises issuing a first election call message; receiving candidacy announcement messages from one or more leader candidate nodes in a specified time period; selecting a victor from among all leader candidate nodes from which candidacy announcement messages are received; receiving one or more victor announcement messages from one or more leader victor nodes for a second specified time period; resolving zero or more collisions among the victor announcement messages to result in selecting the leader node. One embodiment provides a dynamic secure protocol for electing a key server, such as a key server that is suited for use with a group key exchange protocol such as the Group Domain of Interpretation (GDOI).Type: GrantFiled: July 22, 2003Date of Patent: September 2, 2008Assignee: Cisco Technology, Inc.Inventors: Geoffrey Huang, Brian Weis
-
Patent number: 7228421Abstract: A technique is disclosed for generating control messages to be transmitted from a first network device to a second network device in a data network. A first control message to be generated at the first network device is determined. Reason information relating to at least one reason for generating the first control message is identified. The first control message is then generated at the first network device, and included the identified reason information. The first control message may be transmitted to at least one other network device in the network, including the second network device. When the first control message is received at the second network device, the reason information included in the first control message is identified. An appropriate response, based, at least in part, upon the reason information provided in the first control message, may then be determined and implemented at the second network device.Type: GrantFiled: June 27, 2001Date of Patent: June 5, 2007Assignee: Cisco Technology, Inc.Inventors: Geoffrey Huang, Jan Vilhuber