Patents by Inventor John Chiong

John Chiong has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20100217819
    Abstract: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.
    Type: Application
    Filed: April 30, 2010
    Publication date: August 26, 2010
    Applicant: A10 NETWORKS, INC.
    Inventors: Lee Chen, John Chiong, Xin Wang
  • Patent number: 7716378
    Abstract: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.
    Type: Grant
    Filed: October 17, 2006
    Date of Patent: May 11, 2010
    Assignee: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Xin Wang
  • Patent number: 7647635
    Abstract: A system and method for resolving an identity includes a security console, which displays security information regarding a secure network. The security information includes at least a first identity used to access the secure network. An operator selects the first identity, and the security console sends it to a resolver. The resolver connects with an identity server to find an access session record with an identity matching the first identity. A second identity is extracted from this record, and the resolver returns a result that includes the second identity. The security console displays the second identity; The first identity can be a user identity of a user, where the second identity is corresponding host identity, or vise versa. In this manner, an efficient interface to security information is provided to an operator, where the operator may resolve a user/host identity to a host/user identity interactively.
    Type: Grant
    Filed: November 2, 2006
    Date of Patent: January 12, 2010
    Assignee: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Philip Kwan
  • Patent number: 7552126
    Abstract: Systems and methods of managing access records of user access to a secure data network include an access record gateway and an access record datastore; the access record gateway being in communication with an access server of the secure data network; and the access record datastore being in communication with the access record gateway. The access record gateway acquires user access information, such as time information; records the user access information in at least one access record; and stores the at least one access record in the access record datastore. The access record gateway also acquires user access activity information, such as user access termination information, and updates previously recorded user access information with the user access activity information. The at least one access record includes a plurality of sub-records, selected from a list including a user information sub-record, a network information sub-record, and a time information sub-record.
    Type: Grant
    Filed: June 2, 2006
    Date of Patent: June 23, 2009
    Assignee: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Phillip Kwan
  • Publication number: 20080229418
    Abstract: Systems and methods adapted to customize a security log analyzer to recognize a security log, the system including at least one network security device for processing data traffic on a data network, the network security device associated with at least one computing device, and adapted to generate a security log, the system further including rule builder software adapted to generate a rule for recognizing at least one item in a security log and a log analyzer adapted to apply the rule in analyzing a security log.
    Type: Application
    Filed: March 14, 2007
    Publication date: September 18, 2008
    Applicant: A10 NETWORKS INC.
    Inventors: Lee Chen, John Chiong, Dennis I. Oshiba
  • Publication number: 20080148357
    Abstract: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.
    Type: Application
    Filed: October 17, 2006
    Publication date: June 19, 2008
    Applicant: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Xin Wang
  • Publication number: 20080109887
    Abstract: A system and method for resolving an identity includes a security console, which displays security information regarding a secure network. The security information includes at least a first identity used to access the secure network. An operator selects the first identity, and the security console sends it to a resolver. The resolver connects with an identity server to find an access session record with an identity matching the first identity. A second identity is extracted from this record, and the resolver returns a result that includes the second identity. The security console displays the second identity; The first identity can be a user identity of a user, where the second identity is corresponding host identity, or vise versa. In this manner, an efficient interface to security information is provided to an operator, where the operator may resolve a user/host identity to a host/user identity interactively.
    Type: Application
    Filed: November 2, 2006
    Publication date: May 8, 2008
    Applicant: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Philip Kwan
  • Publication number: 20070282855
    Abstract: Systems and methods of managing access records of user access to a secure data network include an access record gateway and an access record datastore; the access record gateway being in communication with an access server of the secure data network; and the access record datastore being in communication with the access record gateway. The access record gateway acquires user access information, such as time information; records the user access information in at least one access record; and stores the at least one access record in the access record datastore. The access record gateway also acquires user access activity information, such as user access termination information, and updates previously recorded user access information with the user access activity information. The at least one access record includes a plurality of sub-records, selected from a list including a user information sub-record, a network information sub-record, and a time information sub-record.
    Type: Application
    Filed: June 2, 2006
    Publication date: December 6, 2007
    Applicant: A10 Networks Inc.
    Inventors: Lee Chen, John Chiong, Phillip Kwan
  • Publication number: 20070271598
    Abstract: Systems and methods of authenticating user access based on an access point to a secure data network include a secure data network having a plurality of a network access points serving as entry points for a user to access the secure data network using a user device. The user is associated with a user identity, each network access point with a network access point identity. The user uses a user device to send an access request, requesting access to the secure data network, to the network access point, which then sends an authentication request to an identity server. The identity server processes the authentication request, by validating the combination of the user identity and the network access point identity, and responds with an authentication response, granting or denying access, as communicated to the user device via an access response. The secure data network may comprise an application level secure data network, in which the user uses the user device to request access to a network application.
    Type: Application
    Filed: May 16, 2006
    Publication date: November 22, 2007
    Applicant: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Yang Yu
  • Publication number: 20070180101
    Abstract: A system and method are disclosed that may include receiving a first event log for a data network user; identifying the user that is the subject of the first event log; updating a user activity record, within stored user activity records, with activity information included in the first event log, the activity information being represented in a first format in the first event log; and repeating the steps of receiving, identifying, and updating for at least one additional event log having activity information stored therein in at least one format other than the first format.
    Type: Application
    Filed: January 10, 2006
    Publication date: August 2, 2007
    Inventors: Lee Chen, Rishi Sampat, John Chiong, Dennis Oshiba