Patents by Inventor Manish Singhvi

Manish Singhvi has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20240121087
    Abstract: Systems and methods are disclosed for acknowledgement-based retirement of expired secure association keys (SAK). A new SAK is generated by a key server. The new SAK is transmitted to members of a connectivity association (CA). The new SAK for key server ingress traffic is installed. An ingress SAK installation acknowledgement is received from the members of the CA. The new SAK for key server egress traffic is installed at the key server, based on receiving the ingress SAK installation acknowledgement from the members of the CA. A key server egress SAK installation notification is transmitted to the members of the CA A prior secure association key is retired after a configurable SAK retirement buffer delay in response to an earlier occurrence of either: receipt of an egress SAK installation acknowledgement from the members of the CA and expiration of a SAK retirement buffer delay, or expiration of a SAK retirement timeout.
    Type: Application
    Filed: October 7, 2022
    Publication date: April 11, 2024
    Inventors: Sourav BASU, Tarun Jaswanth, Kaustav MAJUMDAR, Manish SINGHVI
  • Publication number: 20230412702
    Abstract: In general, the disclosure relates to a method for redirecting a user to a captive portal. The method includes trapping an incoming frame originating from a host, where the incoming frame comprises a L2 header and a payload, wherein the payload specifies information associated with an external server, wherein the user of the host has not been authenticated by the captive portal at a time when the incoming frame is trapped, extracting the L2 header, an L3 header, and the payload from the incoming frame, forwarding the L3 header and the payload towards a redirection server executing on the network device, wherein the redirection server is configured to generate a redirection response based on the payload; encapsulating the redirection response to obtain an L3 response packet, encapsulating the L3 response packet using information from the L2 header to obtain an output frame, and transmitting the output frame towards the host.
    Type: Application
    Filed: June 15, 2023
    Publication date: December 21, 2023
    Inventors: Leandro Lisboa Penz, Arun Ajith Surendranath, Ganesan Rajagopal, Manish Singhvi
  • Publication number: 20230403303
    Abstract: A method for managing a group of secured network devices. The method includes detecting, by a switchover agent operating in a secured network device of the group of secured network devices, a switchover between two supervisors operating in the secured network device, based on the detecting: generating a modified heartbeat packet, wherein the modified heartbeat packet comprises a suspension time that is significantly larger than a heartbeat interval, and sending the modified heartbeat packet to a second secured network device of the group of secured network devices.
    Type: Application
    Filed: June 8, 2022
    Publication date: December 14, 2023
    Inventors: Sourav Basu, Tarun Jain, Kaustav Majumdar, Manish Singhvi
  • Publication number: 20230379328
    Abstract: In general, embodiments relate to a method for managing a network device, including receiving an incoming frame originating from a host, where the incoming frame includes IP address of the host and a payload specifying information associated with an external server. The further includes determining, using the IP address of the host and an IP address to segment identifier (ID) mapping, that the host is associated with a first segment, in response to the determining, forwarding the incoming frame towards a redirection server executing on the network device, where the first segment is associated with a first policy and where the first policy specifies that the incoming frame is to be forwarded to the redirection server.
    Type: Application
    Filed: May 19, 2022
    Publication date: November 23, 2023
    Inventor: Manish Singhvi
  • Publication number: 20230308262
    Abstract: Embodiments allow a network device whose hardware limits an Association Number (AN) to only {0, 1}, to be part of Media Access Control security (MACsec). Upon detecting a network device as being AN-limited, that device’s priority value is assigned a maximum value, thereby ensuring election of the AN-limited device as the key server. The {0, 1} AN of the key server is used to generate a Secure Association Key (SAK) used for MACsec. Upon subsequent rekeying, the AN-limited key server automatically cycles to a next AN (either 0 or 1) to generate a new SAK, where that next AN is also recognized by other network devices. In this manner, the AN-limited network device can participate in the MACsec without encountering ANs (e.g., {2, 3}) that it does not recognize.
    Type: Application
    Filed: March 28, 2022
    Publication date: September 28, 2023
    Inventors: Kaustav Majumdar, Manish Singhvi
  • Patent number: 11722578
    Abstract: In general, the disclosure relates to a method for redirecting a user to a captive portal. The method includes trapping an incoming frame originating from a host, where the incoming frame comprises a L2 header and a payload, wherein the payload specifies information associated with an external server, wherein the user of the host has not been authenticated by the captive portal at a time when the incoming frame is trapped, extracting the L2 header, an L3 header, and the payload from the incoming frame, forwarding the L3 header and the payload towards a redirection server executing on the network device, wherein the redirection server is configured to generate a redirection response based on the payload; encapsulating the redirection response to obtain an L3 response packet, encapsulating the L3 response packet using information from the L2 header to obtain an output frame, and transmitting the output frame towards the host.
    Type: Grant
    Filed: January 22, 2021
    Date of Patent: August 8, 2023
    Assignee: ARISTA NETWORKS, INC.
    Inventors: Leandro Lisboa Penz, Arun Ajith Surendranath, Ganesan Rajagopal, Manish Singhvi
  • Patent number: 11658976
    Abstract: Embodiments of a method for redirecting, by a network device, a host to a captive portal are disclosed. The method includes receiving an incoming frame originating from the host. The incoming frame has a payload specifying information associated with an external server. A user of the host has not been authenticated by the captive portal at a time when the incoming frame is received by the network device. The network device matches at least a portion of the incoming frame to a custom redirect rule of a unified access control list (ACL) implemented by the network device. In response to the matching, the network device forwards the incoming frame towards an internal redirection server executing on the network device. The network device receives a redirection frame from the internal redirection server. The payload of the redirection frame is generated by the internal redirection server using at least a portion of the incoming frame. The redirection frame is transmitted towards the host.
    Type: Grant
    Filed: March 12, 2021
    Date of Patent: May 23, 2023
    Assignee: ARISTA NETWORKS, INC.
    Inventors: Manish Singhvi, Ganesan Rajagopal, Ziqian Xu, Leandro Penz
  • Publication number: 20220321560
    Abstract: In general, the disclosure relates to a method for creating segment mapping in a network, by a network device. The method includes receiving a segment identification (ID) for a client device of the network from an authentication system. The segment ID identifies a segment of the network including the client device and the network device wherein the segment ID is associated with a media access control (MAC) address of the client device. The network device or a network management system (NMS) determines an internet protocol (IP) address of the client device and the network device creates an IP address to segment ID mapping for the client device using the IP address. The IP address to segment ID mapping is provided to the NMS for distribution to remaining network devices of the network. At least one packet of the client device is processed using the IP address to segment ID mapping.
    Type: Application
    Filed: May 21, 2021
    Publication date: October 6, 2022
    Inventors: John French, Manish Singhvi
  • Publication number: 20220239654
    Abstract: In general, the disclosure relates to a method for redirecting, by a network device, a host to a captive portal. The method includes receiving an incoming frame originating from the host. The incoming frame has a payload specifying information associated with an external server. A user of the host has not been authenticated by the captive portal at a time when the incoming frame is received by the network device. The network device matches at least a portion of the incoming frame to a custom redirect rule of a unified access control list (ACL) implemented by the network device. In response to the matching, the network device forwards the incoming frame towards an internal redirection server executing on the network device. The network device receives a redirection frame from the internal redirection server. The payload of the redirection frame is generated by the internal redirection server using at least a portion of the incoming frame. The redirection frame is transmitted towards the host.
    Type: Application
    Filed: March 12, 2021
    Publication date: July 28, 2022
    Inventors: Manish Singhvi, Ganesan Rajagopal, Ziqian Xu, Leandro Penz
  • Publication number: 20220174129
    Abstract: In general, the disclosure relates to a method for redirecting a user to a captive portal. The method includes trapping an incoming frame originating from a host, where the incoming frame comprises a L2 header and a payload, wherein the payload specifies information associated with an external server, wherein the user of the host has not been authenticated by the captive portal at a time when the incoming frame is trapped, extracting the L2 header, an L3 header, and the payload from the incoming frame, forwarding the L3 header and the payload towards a redirection server executing on the network device, wherein the redirection server is configured to generate a redirection response based on the payload; encapsulating the redirection response to obtain an L3 response packet, encapsulating the L3 response packet using information from the L2 header to obtain an output frame, and transmitting the output frame towards the host.
    Type: Application
    Filed: January 22, 2021
    Publication date: June 2, 2022
    Inventors: Leandro Lisboa Penz, Arun Ajith Surendranath, Ganesan Rajagopal, Manish Singhvi