Patents by Inventor Mohan Ram

Mohan Ram has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11463425
    Abstract: Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.
    Type: Grant
    Filed: October 13, 2017
    Date of Patent: October 4, 2022
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Sung-Wook Han
  • Patent number: 11330469
    Abstract: An 802.11-compliant device for high throughput is disclosed. A plurality of TCP packets received in a buffer for transmission are stored. The plurality of TCP packets can be aggregated as A-MSDU sub-frames to form a A-MSDU frame in accordance with an IEEE 802.11 standard. Additionally, a plurality of A-MSDU frames can be aggregated as A-MPDU sub-frames to form a A-MPDU frame. The A-MPDU frame is compliant with a number of allowable sub-frames and a maximum size in accordance with an 802.11 standard. The A-MPDU frame is sent for transmission as an IEEE 802.11 packet.
    Type: Grant
    Filed: June 27, 2016
    Date of Patent: May 10, 2022
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Sung-Wook Han
  • Patent number: 10880749
    Abstract: Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.
    Type: Grant
    Filed: February 27, 2018
    Date of Patent: December 29, 2020
    Assignee: Fortinet, Inc.
    Inventors: Sung-Wook Han, Mohan Ram
  • Patent number: 10652905
    Abstract: Network devices are steered to preferred access points using a probability function. A probe request for connection is received from a network device. The probe request can be from a network device attempting to use a wireless network (e.g., a IEEE 802.11-type network or other suitable type of network). A probability function that defines a likelihood of granting the network device a connection is used to determine whether to accept or deny the response. The probe response is then sent to the network device.
    Type: Grant
    Filed: May 28, 2018
    Date of Patent: May 12, 2020
    Assignee: Fortinet, Inc.
    Inventors: Sung-Wook Han, Mohan Ram
  • Patent number: 10225764
    Abstract: Uplink medium access control on per-wireless device level for a specific user. An access point sends a beacon frame to a wireless device. The beacon frame includes a BSSID that is unique to the wireless device. The beacon frame also includes embedded uplink configurations specifying uplink medium access for the wireless device. In one embodiment, a controller recognizes a device or user associated with the device, and sends corresponding uplink configurations for embedding in a subsequent beacon frame.
    Type: Grant
    Filed: September 24, 2015
    Date of Patent: March 5, 2019
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Sung-Wook Han, Berend Dunsbergen, Vaduvur Bharghavan, Joseph Epstein
  • Publication number: 20180343660
    Abstract: Network devices are steered to preferred access points using a probability function. A probe request for connection is received from a network device. The probe request can be from a network device attempting to use a wireless network (e.g., a IEEE 802.11-type network or other suitable type of network). A probability function that defines a likelihood of granting the network device a connection is used to determine whether to accept or deny the response. The probe response is then sent to the network device.
    Type: Application
    Filed: May 28, 2018
    Publication date: November 29, 2018
    Inventors: Sung-Wook HAN, Mohan RAM
  • Patent number: 10129755
    Abstract: A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.
    Type: Grant
    Filed: February 27, 2018
    Date of Patent: November 13, 2018
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Anil Kaushik
  • Publication number: 20180262911
    Abstract: Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.
    Type: Application
    Filed: February 27, 2018
    Publication date: September 13, 2018
    Inventors: Sung-Wook HAN, Mohan Ram
  • Publication number: 20180255462
    Abstract: A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.
    Type: Application
    Filed: February 27, 2018
    Publication date: September 6, 2018
    Inventors: Mohan Ram, Anil KAUSHIK
  • Publication number: 20180152425
    Abstract: Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.
    Type: Application
    Filed: October 13, 2017
    Publication date: May 31, 2018
    Inventors: Mohan RAM, Sung-Wook HAN
  • Patent number: 9986576
    Abstract: Network devices are steered to preferred access points using a probability function. A probe request for connection is received from a network device. The probe request can be from a network device attempting to use a wireless network (e.g., a IEEE 802.11-type network or other suitable type of network). A probability function that defines a likelihood of granting the network device a connection is used to determine whether to accept or deny the response. The probe response is then sent to the network device.
    Type: Grant
    Filed: September 15, 2016
    Date of Patent: May 29, 2018
    Assignee: Fortinet, INC
    Inventors: Sung-Wook Han, Mohan Ram
  • Patent number: 9980145
    Abstract: Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.
    Type: Grant
    Filed: May 5, 2016
    Date of Patent: May 22, 2018
    Assignee: Fortinet, Inc.
    Inventors: Sung-Wook Han, Mohan Ram
  • Patent number: 9949131
    Abstract: A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.
    Type: Grant
    Filed: May 4, 2017
    Date of Patent: April 17, 2018
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Anil Kaushik
  • Patent number: 9917752
    Abstract: A system and method for optimizing voice communications in a wireless network including an AP having a message waiting time that provides proper QoS while losing minimal communication bandwidth. The QoS may be responsive to the amount of user traffic in both the AP and neighboring APs. The method may include setting parameters for each level of QoS in response to a measure of the degree of contention for that level of QoS, and in response to a measure of the degree of contention for those levels of QoS with higher priority, and setting waiting time parameters in response to a stochastic model of contention at each level of QoS. Operational parameters might include contention window time, AIFS time, and back-off value(s), and might be modified in response to message QoS.
    Type: Grant
    Filed: June 24, 2011
    Date of Patent: March 13, 2018
    Assignee: Fortinet, LLC
    Inventors: Mohan Ram, Vaduvur Bharghavan
  • Patent number: 9906650
    Abstract: A system and method for optimizing voice communications in a wireless network including an AP having a message waiting time that provides proper QoS while losing minimal communication bandwidth. The QoS may be responsive to the amount of user traffic in both the AP and neighboring APs. The method may include setting parameters for each level of QoS in response to a measure of the degree of contention for that level of QoS, and in response to a measure of the degree of contention for those levels of QoS with higher priority, and setting waiting time parameters in response to a stochastic model of contention at each level of QoS. Operational parameters might include contention window time, AIFS time, and back-off value(s), and might be modified in response to message QoS.
    Type: Grant
    Filed: January 30, 2015
    Date of Patent: February 27, 2018
    Assignee: Fortinet, LLC
    Inventors: Mohan Ram, Vaduvur Bharghavan
  • Patent number: 9838369
    Abstract: Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.
    Type: Grant
    Filed: February 13, 2016
    Date of Patent: December 5, 2017
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Sung-Wook Han
  • Publication number: 20170303130
    Abstract: A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.
    Type: Application
    Filed: May 4, 2017
    Publication date: October 19, 2017
    Applicant: Meru Networks (Patent Prosecution)
    Inventors: Mohan Ram, Anil KAUSHIK
  • Patent number: 9794801
    Abstract: Reliable multicast delivery in wireless communication, even when a WS doesn't know its AP, is determined at the AP without the sending device. Multicast packets are received at each AP having destinations. Without altering those packets, the AP encapsulates them in an A-MSDU packet. Each A-MSDU packet is sent individually to each destination, and might encapsulate more than one multicast packet. Destinations might receive two streaming messages faster than if sent separately. AP's might choose a 1st multiple of multicast packets from a 1st source, a 2nd, different, multiple of multicast packets from a 2nd source, and a single multicast packet from a 3rd source. Individualized optimization of transmission parameters for each A-MSDU packet and each multicast packet therein. Individualized optimization of transmission parameters for the A-MSDU packet for each destination. The AP collectively optimizes delivery of distinct multicast packets to different destinations.
    Type: Grant
    Filed: February 22, 2011
    Date of Patent: October 17, 2017
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Vaduvur Bharghavan
  • Publication number: 20170245152
    Abstract: Techniques which prevent rogue devices from continued access to a wireless communication system. A control element directs access points as to which mobile stations to service. Each access point maintains a record of the mobile stations it is servicing. At the direction of the control element, one or more access points send ACK (acknowledgement) messages when hearing messages from a rogue device. When the rogue device sends a message, it expects an ACK message in response, but those additional ACK messages interfere with the responsive ACK message, causing the rogue device to never hear the responsive ACK message. The rogue device assumes its message was not received, so it retries sending of that message. When the rogue device retries sending of its message, the responsive ACK message is similarly interfered with, until the rogue device concludes that its connection has been lost.
    Type: Application
    Filed: May 5, 2016
    Publication date: August 24, 2017
    Inventors: Sung-Wook HAN, Mohan Ram
  • Patent number: 9681299
    Abstract: A spoofed management frame is sent to an unauthorized access point (AP) on behalf of a station from an authorized AP, using a media access control (MAC) address of the station. The spoofed frame triggers a security association (SA) query from an unauthorized AP to reestablish valid communications. An acknowledgment (ACK) frame sent from the client to the unauthorized AP responsive to the SA query request is detected by the AP. A probe response is sent to the client. The probe response includes a channel switching element. The channel switching prevents the client from completing the SA process before a time out.
    Type: Grant
    Filed: July 8, 2013
    Date of Patent: June 13, 2017
    Assignee: Fortinet, Inc.
    Inventors: Mohan Ram, Anil Kaushik