Patents by Inventor Jerome Tollet

Jerome Tollet has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12706847
    Abstract: Disclosed is a method for load balancing at the source side rather than the destination side of a network. Destination networks can communicate with source load balancers by transmitting network protocol advertisements such as border gateway protocol (BGP) advertisements. The advertisements can communicate prefixes representing available subnets for load balancing purposes. The source load balancer would then load balance and transmit the network traffic along a path made up at least in part by the prefixes advertised by the network.
    Type: Grant
    Filed: October 30, 2024
    Date of Patent: August 11, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Rashmi Garg, Jon Langemak, Jerome Tollet, Benoit Ganne, Arthur de Kerhor
  • Publication number: 20260214061
    Abstract: The systems and methods disclosed herein provide for coalescing data packets into jumbo frames in order to maximize the throughputs inside the service provider Local Area Network (LAN), thereby increasing the amount of traffic forwarded between internal services. The systems and methods outlined herein enable a source service on a LAN to receive a plurality of data packets from a public cloud-based network (e.g., the Internet) having a packet size limit less than the MTU limit of the LAN, and coalesce the plurality of data packets into a jumbo frame having a size based on the MTU limit of the LAN. The jumbo frame is then transmitted over the LAN to a destination service on the LAN. The destination service then separates the jumbo frame back into the plurality of data packets for further transmission back to the public cloud-based network.
    Type: Application
    Filed: March 19, 2026
    Publication date: July 23, 2026
    Inventors: Arthur de Kerhor, Jerome Tollet, Nathan Roland Maryan Skrzypczak, Aloÿs Christophe Augustin, Mohammed Hawari
  • Patent number: 12689583
    Abstract: Proposed herein at techniques for scalable network traffic steering in a multi-tenant network. In one aspect, a method includes receiving, at an ingress of a multi-tenant network, a data packet, the data packet including a Virtual Network Identifier (VNI) identifying a corresponding tenant for the data packet in the multi-tenant network, and determining, at the ingress, a corresponding cluster of routers for processing the data packet based on the VNI, wherein the corresponding cluster of routers is one of a plurality of clusters of routers in the multi-tenant network. The method further includes forwarding the data packet to a router in the corresponding cluster of routers for processing.
    Type: Grant
    Filed: May 30, 2023
    Date of Patent: July 21, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Mohammed Hawari, Jerome Tollet, Benoit Ganne, Arthur de Kerhor
  • Patent number: 12665833
    Abstract: The present technology pertains to receiving, by a multi-tenanted cloud-native headend, network traffic from a source that is directed to a destination within a network of a first tenant, where the network traffic is routed using BGP over a multi-tenanted BGP network, where the multi-tenanted BGP network utilizes route isolation to isolate the network of the first tenant from networks of other tenants making use of the multi-tenanted BGP network, mapping the received network traffic based on at least a source IP, source port, and virtual network interface (VNI) to a port associated with the network of the first tenant over the isolated BGP route, where the mapping is a stateful mapping, where the mapping is also potentially based on other information associated with the network traffic, and directing the received network traffic to a local address in the network of the first tenant.
    Type: Grant
    Filed: November 7, 2024
    Date of Patent: June 23, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Jerome Tollet, Arthur de Kerhor, Benoit Ganne, Dawn Minion
  • Publication number: 20260121984
    Abstract: Disclosed is a method for load balancing at the source side rather than the destination side of a network. Destination networks can communicate with source load balancers by transmitting network protocol advertisements such as border gateway protocol (BGP) advertisements. The advertisements can communicate prefixes representing available subnets for load balancing purposes. The source load balancer would then load balance and transmit the network traffic along a path made up at least in part by the prefixes advertised by the network.
    Type: Application
    Filed: October 30, 2024
    Publication date: April 30, 2026
    Inventors: Rashmi Garg, Jon Langemak, Jerome Tollet, Benoit Ganne, Arthur de Kerhor
  • Patent number: 12615216
    Abstract: The systems and methods disclosed herein provide for coalescing data packets into jumbo frames in order to maximize the throughputs inside the service provider Local Area Network (LAN), thereby increasing the amount of traffic forwarded between internal services. The systems and methods outlined herein enable a source service on a LAN to receive a plurality of data packets from a public cloud-based network (e.g., the Internet) having a packet size limit less than the MTU limit of the LAN, and coalesce the plurality of data packets into a jumbo frame having a size based on the MTU limit of the LAN. The jumbo frame is then transmitted over the LAN to a destination service on the LAN. The destination service then separates the jumbo frame back into the plurality of data packets for further transmission back to the public cloud-based network.
    Type: Grant
    Filed: November 29, 2023
    Date of Patent: April 28, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Arthur de Kerhor, Jerome Tollet, Nathan Roland Maryan Skrzypczak, Aloÿs Christophe Augustin, Mohammed Hawari
  • Publication number: 20260039721
    Abstract: Techniques for utilizing a portion of a communication session identifier (e.g., a Session-ID, an SPI, a CID, a DCID, and/or the like) to indicate a target routing device (e.g., a VPN and/or ZTNA termination device) for establishing control plane session(s) and/or data plane session(s) at wire-speed in a networked computing environment. The routing device(s) of a networked computing environment may generate a communication session identifier and send the communication session identifier to the client device, such that subsequent packets send from the client device may be forwarded to the proper routing device indicated by the communication session identifier for establishment of one or more data plane sessions. Additionally, data plane sessions may be established using a Resumed Handshake rather than a full handshake that is typically required, as Session Resumption utilizes the assigned communication session identifier for mapping.
    Type: Application
    Filed: October 6, 2025
    Publication date: February 5, 2026
    Inventors: Vincent E. Parla, Jerome Tollet, Aloys Christophe Augustin, Mohammed Hawari
  • Publication number: 20250330453
    Abstract: Techniques for routing Internet Protocol security (IPsec) data packets. An index is assigned to a Security Parameter Index (SPI) header of the IPsec data packet. The index includes information for routing the data packet to a particular Encapsulating Security Payload (ESP) processor. The data packet can be routed using techniques that are analogous to conventional routing protocols such as IPv4 routing protocol. This allows the data packet to be routed using less expensive routing protocols rather than relying solely on more expensive load balancing techniques to route the data packet. This also advantageously allows the data packet to be routed employing routing techniques developed over decades of routing protocol development.
    Type: Application
    Filed: June 30, 2025
    Publication date: October 23, 2025
    Inventors: William Mark Townsley, Edward Albert Warnicke, Jerome Tollet, Aloys Augustin, Andrew Yourtchenko, Giles Douglas Yorke Heron
  • Patent number: 12445527
    Abstract: Techniques for utilizing a portion of a communication session identifier (e.g., a Session-ID, an SPI, a CID, a DCID, and/or the like) to indicate a target routing device (e.g., a VPN and/or ZTNA termination device) for establishing control plane session(s) and/or data plane session(s) at wire-speed in a networked computing environment. The routing device(s) of a networked computing environment may generate a communication session identifier and send the communication session identifier to the client device, such that subsequent packets send from the client device may be forwarded to the proper routing device indicated by the communication session identifier for establishment of one or more data plane sessions. Additionally, data plane sessions may be established using a Resumed Handshake rather than a full handshake that is typically required, as Session Resumption utilizes the assigned communication session identifier for mapping.
    Type: Grant
    Filed: October 4, 2023
    Date of Patent: October 14, 2025
    Assignee: Cisco Technology, Inc.
    Inventors: Vincent E. Parla, Jerome Tollet, Aloys Christophe Augustin, Mohammed Hawari
  • Publication number: 20250247321
    Abstract: The present technology pertains to receiving, by a multi-tenanted cloud-native headend, network traffic from a source that is directed to a destination within a network of a first tenant, where the network traffic is routed using BGP over a multi-tenanted BGP network, where the multi-tenanted BGP network utilizes route isolation to isolate the network of the first tenant from networks of other tenants making use of the multi-tenanted BGP network, mapping the received network traffic based on at least a source IP, source port, and virtual network interface (VNI) to a port associated with the network of the first tenant over the isolated BGP route, where the mapping is a stateful mapping, where the mapping is also potentially based on other information associated with the network traffic, and directing the received network traffic to a local address in the network of the first tenant.
    Type: Application
    Filed: November 7, 2024
    Publication date: July 31, 2025
    Inventors: Jerome Tollet, Arthur de Kerhor, Benoit Ganne, Dawn Minion
  • Patent number: 12375463
    Abstract: Techniques for routing Internet Protocol security (IPsec) data packets. An index is assigned to a Security Parameter Index (SPI) header of the IPsec data packet. The index includes information for routing the data packet to a particular Encapsulating Security Payload (ESP) processor. The data packet can be routed using techniques that are analogous to conventional routing protocols such as IPv4 routing protocol. This allows the data packet to be routed using less expensive routing protocols rather than relying solely on more expensive load balancing techniques to route the data packet. This also advantageously allows the data packet to be routed employing routing techniques developed over decades of routing protocol development.
    Type: Grant
    Filed: April 26, 2023
    Date of Patent: July 29, 2025
    Assignee: Cisco Technology, Inc.
    Inventors: William Mark Townsley, Edward Albert Warnicke, Jerome Tollet, Aloys Augustin, Andrew Yourtchenko, Giles Douglas Yorke Heron
  • Publication number: 20250175437
    Abstract: The systems and methods disclosed herein provide for coalescing data packets into jumbo frames in order to maximize the throughputs inside the service provider Local Area Network (LAN), thereby increasing the amount of traffic forwarded between internal services. The systems and methods outlined herein enable a source service on a LAN to receive a plurality of data packets from a public cloud-based network (e.g., the Internet) having a packet size limit less than the MTU limit of the LAN, and coalesce the plurality of data packets into a jumbo frame having a size based on the MTU limit of the LAN. The jumbo frame is then transmitted over the LAN to a destination service on the LAN. The destination service then separates the jumbo frame back into the plurality of data packets for further transmission back to the public cloud-based network.
    Type: Application
    Filed: November 29, 2023
    Publication date: May 29, 2025
    Inventors: Arthur de Kerhor, Jerome Tollet, Nathan Roland Maryan Skrzypczak, Aloÿs Christophe Augustin, Mohammed Hawari
  • Publication number: 20250119471
    Abstract: Techniques for utilizing a portion of a communication session identifier (e.g., a Session-ID, an SPI, a CID, a DCID, and/or the like) to indicate a target routing device (e.g., a VPN and/or ZTNA termination device) for establishing control plane session(s) and/or data plane session(s) at wire-speed in a networked computing environment. The routing device(s) of a networked computing environment may generate a communication session identifier and send the communication session identifier to the client device, such that subsequent packets send from the client device may be forwarded to the proper routing device indicated by the communication session identifier for establishment of one or more data plane sessions. Additionally, data plane sessions may be established using a Resumed Handshake rather than a full handshake that is typically required, as Session Resumption utilizes the assigned communication session identifier for mapping.
    Type: Application
    Filed: October 4, 2023
    Publication date: April 10, 2025
    Inventors: Vincent E. Parla, Jerome Tollet, Aloys Christophe Augustin, Mohammed Hawari
  • Patent number: 12218908
    Abstract: Systems, methods, and computer-readable media are provided for securely advertising autoconfigured prefixes in a cloud environment. In some examples, a method can include, receiving, by a first router, an indication of an available network address prefix. In some aspects, the method can also include selecting, by the first router, a first network address prefix that is within the available network address prefix, wherein the first network address prefix provides at least one route to one or more network elements associated with the first router. In some cases, the method may further include sending, to a second router, a message including a stub registration option that indicates the first network address prefix.
    Type: Grant
    Filed: February 22, 2022
    Date of Patent: February 4, 2025
    Assignee: Cisco Technology, Inc.
    Inventors: Pascal Thubert, Jerome Tollet, Ali Sajassi, Aloÿs Christophe Augustin, Nathan Roland Maryan Skrzypczak, Stephane Litkowski
  • Publication number: 20240406101
    Abstract: Proposed herein at techniques for scalable network traffic steering in a multi-tenant network. In one aspect, a method includes receiving, at an ingress of a multi-tenant network, a data packet, the data packet including a Virtual Network Identifier (VNI) identifying a corresponding tenant for the data packet in the multi-tenant network, and determining, at the ingress, a corresponding cluster of routers for processing the data packet based on the VNI, wherein the corresponding cluster of routers is one of a plurality of clusters of routers in the multi-tenant network. The method further includes forwarding the data packet to a router in the corresponding cluster of routers for processing.
    Type: Application
    Filed: May 30, 2023
    Publication date: December 5, 2024
    Inventors: Mohammed Hawari, Jerome Tollet, Benoit Ganne, Arthur de Kerhor
  • Publication number: 20240364669
    Abstract: Techniques for routing Internet Protocol security (IPsec) data packets. An index is assigned to a Security Parameter Index (SPI) header of the IPsec data packet. The index includes information for routing the data packet to a particular Encapsulating Security Payload (ESP) processor. The data packet can be routed using techniques that are analogous to conventional routing protocols such as IPv4 routing protocol. This allows the data packet to be routed using less expensive routing protocols rather than relying solely on more expensive load balancing techniques to route the data packet. This also advantageously allows the data packet to be routed employing routing techniques developed over decades of routing protocol development.
    Type: Application
    Filed: April 26, 2023
    Publication date: October 31, 2024
    Inventors: William Mark Townsley, Edward Albert Warnicke, Jerome Tollet, Aloys Augustin, Andrew Yourtchenko, Giles Douglas Yorke Heron
  • Patent number: 11943078
    Abstract: Techniques for a hub node, provisioned in a site of a hub and spoke overlay network, to receive, store, and/or forward network routing information associated with a spoke, and send packets directly to spoke(s) that are remote from the hub node. A first hub node may receive a network advertisement including a border gateway protocol (BGP) large community string from a first spoke local to the first hub node. The first hub node may send the BGP large community string to a second hub node remote from the first hub node. The second hub node may decode network routing information from the BGP large community string and store the network routing information locally. The second hub node may send a packet from a second spoke local to the second hub node directly to the first spoke without the data packet being routed via the first hub node.
    Type: Grant
    Filed: July 8, 2022
    Date of Patent: March 26, 2024
    Assignee: Cisco Technology, Inc.
    Inventors: Hari Shankar, Rashmi Garg, Benoit Ganne, Jerome Tollet, Nathan Skrzypczak
  • Publication number: 20240015050
    Abstract: Techniques for a hub node, provisioned in a site of a hub and spoke overlay network, to receive, store, and/or forward network routing information associated with a spoke, and send packets directly to spoke(s) that are remote from the hub node. A first hub node may receive a network advertisement including a border gateway protocol (BGP) large community string from a first spoke local to the first hub node. The first hub node may send the BGP large community string to a second hub node remote from the first hub node. The second hub node may decode network routing information from the BGP large community string and store the network routing information locally. The second hub node may send a packet from a second spoke local to the second hub node directly to the first spoke without the data packet being routed via the first hub node.
    Type: Application
    Filed: July 8, 2022
    Publication date: January 11, 2024
    Inventors: Hari Shankar, Rashmi Garg, Benoit Ganne, Jerome Tollet, Nathan Skrzypczak
  • Publication number: 20230269223
    Abstract: Systems, methods, and computer-readable media are provided for securely advertising autoconfigured prefixes in a cloud environment. In some examples, a method can include, receiving, by a first router, an indication of an available network address prefix. In some aspects, the method can also include selecting, by the first router, a first network address prefix that is within the available network address prefix, wherein the first network address prefix provides at least one route to one or more network elements associated with the first router. In some cases, the method may further include sending, to a second router, a message including a stub registration option that indicates the first network address prefix.
    Type: Application
    Filed: February 22, 2022
    Publication date: August 24, 2023
    Inventors: Pascal Thubert, Jerome Tollet, Ali Sajassi, Aloÿs Christophe Augustin, Nathan Roland Maryan Skrzypczak, Stephane Litkowski
  • Patent number: 11558345
    Abstract: Systems, methods, and computer-readable storage media are provided to populate databases with routing data for containers to eliminate the need for continuously accessing a global discovery service. An example method includes initiating, from a source container operating on a first machine in a first rack, a communication with a destination container operating on a second machine on a second rack, wherein a local database on the first machine does not know an address of the destination container. The method includes accessing a global discovery service to provide the address of the destination container, populating the local database on the first machine with the address of the destination container and routing a packet from the source container to the destination container according to the address of the destination container.
    Type: Grant
    Filed: November 16, 2020
    Date of Patent: January 17, 2023
    Assignee: Cisco Technology, Inc.
    Inventors: Yoann Desmouceaux, Marcel Paul Sosthène Enguehard, Jacques Olivier Samain, Jerome Tollet